Buffer Overflow Vulnerability in Samsung SmartThings Hub
CVE-2018-3863
9.9CRITICAL
Summary
The Samsung SmartThings Hub STH-ETH-250 experiences a vulnerability where the video-core process fails to properly handle user-controlled JSON payloads. This improper extraction of fields can lead to a buffer overflow on the stack, specifically when a strcpy operation attempts to write to a buffer that exceeds its designated capacity of 40 bytes. An attacker can exploit this flaw by crafting an HTTP request with an excessively long 'user' value, thereby triggering the overflow and potentially allowing for unauthorized actions.
Affected Version(s)
SmartThings Hub STH-ETH-250 Firmware version 0.20.17
References
CVSS V3.1
Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved