CVE-2020-11024

MEDIUM

Moonlight iOS/tvOS < 4.0.1 - Man-in-the-Middle Attack via Pairing Process

Title source: llm
STIX 2.1

Description

In Moonlight iOS/tvOS before 4.0.1, the pairing process is vulnerable to a man-in-the-middle attack. The bug has been fixed in Moonlight v4.0.1 for iOS and tvOS.

Scores

CVSS v3 6.1
EPSS 0.0080
EPSS Percentile 52.0%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:L

Details

CWE
CWE-200 CWE-300
Status published
Products (1)
moonlight-stream/moonlight < 4.0.1 (2 CPE variants)
Published Apr 29, 2020
Tracked Since Feb 18, 2026