Buffer Overflow Vulnerability in Samsung SmartThings Hub
CVE-2018-3864

9.9CRITICAL

Key Information:

Vendor
Samsung
Vendor
CVE Published:
20 September 2018

Summary

A buffer overflow vulnerability has been identified in the Samsung SmartThings Hub's WifiScan handler, which could be exploited via the HTTP server. This issue allows attackers to send excessively long input to a 'password' field, leading to a potential overflow of the destination buffer intended for storage. It is crucial for users to be aware of this flaw to prevent unauthorized access and ensure the security of their smart home devices.

Affected Version(s)

SmartThings Hub STH-ETH-250 Firmware version 0.20.17

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.