Stack-Based Buffer Overflow in Samsung SmartThings Hub
CVE-2018-3914
7.5HIGH
What is CVE-2018-3914?
An exploitable stack-based buffer overflow flaw exists in the Samsung SmartThings Hub's video-core HTTP server. It stems from an unsafe 'strcpy' operation during the retrieval of database fields, which does not properly handle long 'sessionToken' values. When an attacker inputs an excessively long session token, it can lead to a buffer overflow, potentially allowing unauthorized access or disruption of service.
Affected Version(s)
SmartThings Hub STH-ETH-250 Firmware version 0.20.17