First published: Wed Jun 11 2014(Updated: )
Samsung iPOLiS Device Manager before 1.8.7 allow remote attackers to execute arbitrary code via unspecified values to the (1) Start, (2) ChangeControlLocalName, (3) DeleteDeviceProfile, (4) FrameAdvanceReader, or other unknown method in the XNSSDKDEVICE.XnsSdkDeviceCtrlForIpInstaller.1 ActiveX control.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung iPOLiS Device Manager | <=1.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3911 has a medium severity rating due to its potential for remote code execution.
To fix CVE-2014-3911, upgrade to Samsung iPOLiS Device Manager version 1.8.7 or later.
CVE-2014-3911 affects all versions of Samsung iPOLiS Device Manager prior to 1.8.7.
Yes, CVE-2014-3911 allows remote attackers to execute arbitrary code, making it exploitable over the network.
CVE-2014-3911 impacts the XNSSDKDEVICE.XnsSdkDeviceCtrlForIpInstaller.1 ActiveX control among other methods.