CVE-2017-3218: High severity samsung magician vulnerability
Published Jun 21, 2017
·Updated
Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.
Affected Software
1 affected component
Samsung Magician=5.0
Event History
Jun 21, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-3218?
CVE-2017-3218 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2017-3218?
To fix CVE-2017-3218, upgrade Samsung Magician to a version higher than 5.0 that validates TLS certificates.
3
What is the impact of CVE-2017-3218?
The impact of CVE-2017-3218 allows attackers to perform man-in-the-middle attacks on software update traffic.
4
How can I mitigate CVE-2017-3218 if I cannot update?
If unable to update, consider disabling the software update feature in Samsung Magician to mitigate risks associated with CVE-2017-3218.
5
Is CVE-2017-3218 still exploitable in later versions?
CVE-2017-3218 is not exploitable in versions of Samsung Magician released after 5.0 that implement proper TLS certificate validation.