CVE-2018-3913: Buffer Overflow
An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 32 bytes. An attacker can send an arbitrarily long "accessKey" value in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3913?
CVE-2018-3913 is considered a high severity vulnerability due to its potential for exploitation through a stack-based buffer overflow.
How do I fix CVE-2018-3913?
To fix CVE-2018-3913, users should update the Samsung SmartThings Hub firmware to a version that addresses this buffer overflow vulnerability.
What products are affected by CVE-2018-3913?
CVE-2018-3913 affects the Samsung SmartThings Hub STH-ETH-250 running firmware version 0.20.17.
Can CVE-2018-3913 be exploited remotely?
Yes, CVE-2018-3913 can be exploited remotely, allowing attackers to send specially crafted requests to the affected device.
What type of vulnerability is CVE-2018-3913?
CVE-2018-3913 is a stack-based buffer overflow vulnerability that occurs during the retrieval of database fields in the SmartThings Hub.