CVE-2018-3873: Buffer Overflow
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 128 bytes. An attacker can send an arbitrarily long "secretKey" value in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3873?
CVE-2018-3873 has a high severity rating due to its ability to cause a buffer overflow.
How do I fix CVE-2018-3873?
To fix CVE-2018-3873, update the Samsung SmartThings Hub to the latest firmware that addresses the buffer overflow vulnerability.
What are the potential consequences of exploiting CVE-2018-3873?
Exploitation of CVE-2018-3873 can lead to remote code execution or crashing of the device.
Which device is affected by CVE-2018-3873?
CVE-2018-3873 affects the Samsung SmartThings Hub STH-ETH-250 running firmware version 0.20.17.
How can I determine if my device is vulnerable to CVE-2018-3873?
You can determine if your device is vulnerable by checking if it is running Samsung SmartThings Hub firmware version 0.20.17.