Buffer Overflow Vulnerability in Samsung SmartThings Hub Video-Core HTTP Server
CVE-2018-3896

9.9CRITICAL

Key Information:

Vendor

Samsung

Vendor
CVE Published:
10 September 2018

What is CVE-2018-3896?

A buffer overflow vulnerability exists in the video-core's HTTP server of Samsung SmartThings Hub affecting firmware version 0.20.17. This flaw allows an attacker to exploit the vulnerability by sending maliciously crafted user-controlled JSON payloads that result in uncontrolled memory overwriting. Specifically, it occurs when the server's handler for clips fails to properly validate the length of the 'correlationId' field. As a result, this can lead to potential execution of arbitrary code or denial of service, thereby compromising the functionality and security of the affected device.

Affected Version(s)

SmartThings Hub STH-ETH-250 Firmware version 0.20.17

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.