Buffer Overflow Vulnerability in Samsung SmartThings Hub Video-Core HTTP Server
CVE-2018-3896
9.9CRITICAL
What is CVE-2018-3896?
A buffer overflow vulnerability exists in the video-core's HTTP server of Samsung SmartThings Hub affecting firmware version 0.20.17. This flaw allows an attacker to exploit the vulnerability by sending maliciously crafted user-controlled JSON payloads that result in uncontrolled memory overwriting. Specifically, it occurs when the server's handler for clips fails to properly validate the length of the 'correlationId' field. As a result, this can lead to potential execution of arbitrary code or denial of service, thereby compromising the functionality and security of the affected device.
Affected Version(s)
SmartThings Hub STH-ETH-250 Firmware version 0.20.17
References
CVSS V3.1
Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved