CVE-2018-3874: Buffer Overflow
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 32 bytes. An attacker can send an arbitrarily long "accessKey" value in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3874?
CVE-2018-3874 is classified as a high-severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2018-3874?
To fix CVE-2018-3874, upgrade the Samsung SmartThings Hub to the latest firmware version that addresses this buffer overflow issue.
What systems are affected by CVE-2018-3874?
CVE-2018-3874 affects the Samsung SmartThings Hub with firmware version 0.20.17.
What type of vulnerability is CVE-2018-3874?
CVE-2018-3874 is a buffer overflow vulnerability in the credentials handler of the HTTP server.
Can an attacker exploit CVE-2018-3874 remotely?
Yes, an attacker can exploit CVE-2018-3874 remotely by sending specially crafted access keys.