CVE-2018-3915 HIGH

CVE-2018-3915

Vendor Samsung
Product SmartThings Hub STH-ETH-250
Published September 21, 2018
Last update September 16, 2024

CVSS base score

7.5/10
Attack vector Local
Attack complexity High
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 64 bytes. An attacker can send an arbitrarily long "bucket" value in order to exploit this vulnerability.

Key dates

02Disclosure timeline

September 21, 2018 CVE published
September 16, 2024 Record updated