CVE-2018-3908: Critical severity samsung sth-eth-250 vulnerability
An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The video-core process incorrectly handles pipelined HTTP requests, which allows successive requests to overwrite the previously parsed HTTP method, URL and body. With the implementation of the onbody callback, defined by sub41734, an attacker can send an HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3908?
CVE-2018-3908 is considered a high severity vulnerability due to its impact on the apparatus handling HTTP requests.
How do I fix CVE-2018-3908?
To fix CVE-2018-3908, upgrade the Samsung SmartThings Hub firmware to a version that is not affected by this vulnerability.
What devices are affected by CVE-2018-3908?
The Samsung SmartThings Hub STH-ETH-250 with firmware version 0.20.17 is vulnerable to CVE-2018-3908.
What type of vulnerability is CVE-2018-3908?
CVE-2018-3908 is an HTTP parsing vulnerability that affects the video-core's HTTP server.
Can CVE-2018-3908 lead to remote exploitation?
Yes, CVE-2018-3908 can potentially allow an attacker to exploit the vulnerability remotely through crafted HTTP requests.