PT-2024-25908 · Nintendo · Nintendo Wii U Os

·

CVE-2024-34454

·

Published

2024-05-26

·

Updated

2024-07-03

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Nintendo Wii U OS version 5.5.5
Description The issue allows man-in-the-middle attackers to forge SSL certificates as though they came from a Root CA. This is due to a secondary verification mechanism that only checks whether a CA is known and ignores the CA details and signature. Additionally, '*' is accepted as a Common Name.
Recommendations For Nintendo Wii U OS version 5.5.5, consider restricting the acceptance of SSL certificates to only those with verified CA details and signatures, and avoid accepting '*' as a Common Name until a proper fix is available. As a temporary workaround, restrict network access to trusted sources to minimize the risk of exploitation.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-34454

Affected Products

Nintendo Wii U Os