PT-2024-25908 · Nintendo · Nintendo Wii U Os
Shutterbug
·
Published
2024-05-26
·
Updated
2024-07-03
·
CVE-2024-34454
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Nintendo Wii U OS version 5.5.5
Description
The issue allows man-in-the-middle attackers to forge SSL certificates as though they came from a Root CA. This is due to a secondary verification mechanism that only checks whether a CA is known and ignores the CA details and signature. Additionally, '*' is accepted as a Common Name.
Recommendations
For Nintendo Wii U OS version 5.5.5, consider restricting the acceptance of SSL certificates to only those with verified CA details and signatures, and avoid accepting '*' as a Common Name until a proper fix is available. As a temporary workaround, restrict network access to trusted sources to minimize the risk of exploitation.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nintendo Wii U Os