Samsung SmartThings Hub video-core... CVE-2018-3912~CVE-2018-3917

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Summary Multiple exploitable stack-based buffer overflow vulnerabilities exist in the retrieval of database fields in the `video-core` HTTP server of the Samsung SmartThings Hub. The `video-core` process insecurely extracts the fields from the "shard" table of its SQLite database, leading to a buffer overflow on the stack. An attacker can send an HTTP request to trigger this vulnerability. ### Tested Versions Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17 ### Product URLs [https://shop.smartthings.com/products/samsung-smartthings-hub](https://shop.smartthings.com/products/samsung-smartthings-hub) ### CVSSv3 Score 7.5 - CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H ### CWE CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') ### Details Samsung produces a series of devices aimed at controlling and monitoring a home, such as wall switches, LED bulbs, thermostats and cameras. One of those is the Samsung SmartThings Hub, a central...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息