Description
The matchmaking servers of Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allow remote attackers to send arbitrary push requests to clients via a RequestSendMessageToPlayers request. For example, ability to send a push message to hundreds of thousands of machines is only restricted on the client side, and can thus be bypassed with a modified client.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-29036 | The matchmaking servers of Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allow remote attackers to send arbitrary push requests to clients via a RequestSendMessageToPlayers request. For example, ability to send a push message to hundreds of thousands of machines is only restricted on the client side, and can thus be bypassed with a modified client. |
References
| Link | Providers |
|---|---|
| https://fromsoftware.jp |
|
| https://github.com/tremwil/ds3-nrssr-rce |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T03:59:24.105Z
Reserved: 2022-01-29T00:00:00.000Z
Link: CVE-2022-24125
No data.
Status : Modified
Published: 2022-03-20T01:15:08.667
Modified: 2024-11-21T06:49:51.670
Link: CVE-2022-24125
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD