Buffer Overflow Vulnerability in Samsung SmartThings Hub Video-Core HTTP Server
CVE-2018-3896
9.9CRITICAL
What is CVE-2018-3896?
A buffer overflow vulnerability exists in the video-core's HTTP server of Samsung SmartThings Hub affecting firmware version 0.20.17. This flaw allows an attacker to exploit the vulnerability by sending maliciously crafted user-controlled JSON payloads that result in uncontrolled memory overwriting. Specifically, it occurs when the server's handler for clips fails to properly validate the length of the 'correlationId' field. As a result, this can lead to potential execution of arbitrary code or denial of service, thereby compromising the functionality and security of the affected device.
Affected Version(s)
SmartThings Hub STH-ETH-250 Firmware version 0.20.17