Buffer Overflow Vulnerability in Samsung SmartThings Hub HTTP Server
CVE-2018-3877

9.9CRITICAL

Key Information:

Vendor
Samsung
Vendor
CVE Published:
21 September 2018

Summary

A buffer overflow issue exists in the credentials handler of the HTTP server within the Samsung SmartThings Hub, specifically for firmware version 0.20.17. This vulnerability arises from the use of 'strncpy', which can lead to an overflow of the destination buffer that is limited to 160 bytes. An attacker could exploit this flaw by sending a specially crafted request with an excessively long 'directory' value, potentially compromising the integrity of the system.

Affected Version(s)

SmartThings Hub STH-ETH-250 Firmware version 0.20.17

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.