Buffer Overflow Vulnerability in Samsung SmartThings Hub
CVE-2018-3863

9.9CRITICAL

Key Information:

Vendor
Samsung
Vendor
CVE Published:
23 August 2018

Summary

The Samsung SmartThings Hub STH-ETH-250 experiences a vulnerability where the video-core process fails to properly handle user-controlled JSON payloads. This improper extraction of fields can lead to a buffer overflow on the stack, specifically when a strcpy operation attempts to write to a buffer that exceeds its designated capacity of 40 bytes. An attacker can exploit this flaw by crafting an HTTP request with an excessively long 'user' value, thereby triggering the overflow and potentially allowing for unauthorized actions.

Affected Version(s)

SmartThings Hub STH-ETH-250 Firmware version 0.20.17

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.