Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-45801 | Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request order and is thereby vulnerable to a MITM attack, potentially allowing an unauthenticated attacker to pair a client by hijacking a legitimate pairing attempt. This bug may also be used by a remote attacker to crash Sunshine. This vulnerability is fixed in 2025.118.151840. |
Thu, 11 Sep 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:lizardbyte:sunshine:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 21 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Jan 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request order and is thereby vulnerable to a MITM attack, potentially allowing an unauthenticated attacker to pair a client by hijacking a legitimate pairing attempt. This bug may also be used by a remote attacker to crash Sunshine. This vulnerability is fixed in 2025.118.151840. | |
| Title | Sunshine improperly enforces pairing protocol request order | |
| Weaknesses | CWE-305 CWE-476 CWE-841 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-21T14:59:35.704Z
Reserved: 2024-10-31T14:12:45.788Z
Link: CVE-2024-51738
Updated: 2025-01-21T14:58:43.918Z
Status : Analyzed
Published: 2025-01-20T16:15:27.667
Modified: 2025-09-11T21:33:04.643
Link: CVE-2024-51738
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:14:01Z
EUVD