VDB

GCVE-110-MAGEIA-2020-475

GCVE-110-MAGEIA-2020-475
Advisory Published
Vulnetix · Advisory published December 29, 2020
For the pairing procedure, the GUI component only presented the friendly 'deviceName' to identify peer devices, which is completely under attacker control. Furthermore the 'deviceName' is transmitted in cleartext in UDP broadcast messages for all other nodes in the network segment to see. Therefore malicious devices can attempt to confuse users by requesting a pairing under the same 'deviceName' to gain access to a system. Now, a sha256 fingerprint of the concatenated public keys of the two involved certificates is displayed. In the initial popup, a prefix of 8 hex digits of the fingerprint is displayed. The full fingerprint is reachable via an additional "view key" button.

Affected Products

VendorProductVersionsPlatforms
Mageiakdeconnect-kde0 (affected), 1.3.4-2.2.mga7 (unaffected)

Browse GCVE Records

74,132 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›