Buffer Overflow Vulnerability in Samsung SmartThings Hub
CVE-2018-3902

9.9CRITICAL

Key Information:

Vendor
Samsung
Vendor
CVE Published:
23 August 2018

Summary

A buffer overflow vulnerability exists in the 'replace' feature of the HTTP server in Samsung's SmartThings Hub STH-ETH-250 devices running firmware version 0.20.17. This issue arises from improper extraction of a user-controlled JSON payload's URL field, which may result in a buffer overflow on the stack. An attacker capable of sending a crafted HTTP request could exploit this vulnerability to execute arbitrary code on the affected device, potentially compromising the security of the smart home environment.

Affected Version(s)

SmartThings Hub STH-ETH-250 Firmware version 0.20.17

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.