Samsung SmartThings Hub video-core... CVE-2018-3872 CNNVD-201807-1950

9.0 AV AC AU C I A
发布: 2018-08-23
修订: 2022-12-13

### Summary An exploitable buffer overflow vulnerability exists in the `credentials` handler of `video-core`'s HTTP server of Samsung SmartThings Hub. The `video-core` process incorrectly extracts the `videoHostUrl` field from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker can send an HTTP request to trigger this vulnerability. ### Tested Versions Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17 ### Product URLs [https://www.smartthings.com/products/smartthings-hub](https://www.smartthings.com/products/smartthings-hub) ### CVSSv3 Score 9.9 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H ### CWE CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') ### Details Samsung produces a series of devices aimed at controlling and monitoring a home, such as wall switches, LED bulbs, thermostats and cameras. One of those is the Samsung SmartThings Hub, a central controller which allows an end user to use their...

0%
暂无可用Exp或PoC
当前有2条受影响产品信息