CVE-2018-3877: Buffer Overflow
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 160 bytes. An attacker can send an arbitrarily long "directory" value in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3877?
CVE-2018-3877 is classified as a critical vulnerability due to its potential for remote exploitation via buffer overflow.
How do I fix CVE-2018-3877?
To fix CVE-2018-3877, update to a patched version of the Samsung STH-ETH-250 firmware that addresses the buffer overflow.
What devices are affected by CVE-2018-3877?
CVE-2018-3877 specifically affects the Samsung SmartThings Hub STH-ETH-250 running firmware version 0.20.17.
What type of attacks can exploit CVE-2018-3877?
CVE-2018-3877 can be exploited by attackers sending crafted HTTP requests that trigger buffer overflow in the credentials handler.
Is CVE-2018-3877 a network vulnerability?
Yes, CVE-2018-3877 is a network vulnerability, as it can be exploited over an HTTP connection.