CVE-2014-3911: Code Injection
Samsung iPOLiS Device Manager before 1.8.7 allow remote attackers to execute arbitrary code via unspecified values to the (1) Start, (2) ChangeControlLocalName, (3) DeleteDeviceProfile, (4) FrameAdvanceReader, or other unknown method in the XNSSDKDEVICE.XnsSdkDeviceCtrlForIpInstaller.1 ActiveX control.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3911?
CVE-2014-3911 has a medium severity rating due to its potential for remote code execution.
How do I fix CVE-2014-3911?
To fix CVE-2014-3911, upgrade to Samsung iPOLiS Device Manager version 1.8.7 or later.
What versions are affected by CVE-2014-3911?
CVE-2014-3911 affects all versions of Samsung iPOLiS Device Manager prior to 1.8.7.
Can CVE-2014-3911 be exploited remotely?
Yes, CVE-2014-3911 allows remote attackers to execute arbitrary code, making it exploitable over the network.
What components of Samsung iPOLiS Device Manager are impacted by CVE-2014-3911?
CVE-2014-3911 impacts the XNSSDKDEVICE.XnsSdkDeviceCtrlForIpInstaller.1 ActiveX control among other methods.