CVE-2018-3879: SQL Injection
An exploitable JSON injection vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly parses the user-controlled JSON payload, leading to a JSON injection which in turn leads to a SQL injection in the video-core database. An attacker can send a series of HTTP requests to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3879?
CVE-2018-3879 is classified as a high severity vulnerability due to the potential for JSON injection.
How do I fix CVE-2018-3879?
To remediate CVE-2018-3879, upgrade the Samsung SmartThings Hub to a firmware version that addresses this vulnerability.
What devices are affected by CVE-2018-3879?
CVE-2018-3879 affects Samsung SmartThings Hub devices with firmware version 0.20.17.
What can an attacker do exploiting CVE-2018-3879?
An attacker exploiting CVE-2018-3879 can perform unauthorized actions by sending specially crafted JSON payloads.
Is the Samsung SmartThings Hub STH-ETH-250 vulnerable to CVE-2018-3879?
Yes, the Samsung SmartThings Hub STH-ETH-250 with firmware version 0.20.17 is vulnerable to CVE-2018-3879.