CVE-2018-3914: Buffer Overflow
An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 2000 bytes. An attacker can send an arbitrarily long "sessionToken" value in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3914?
CVE-2018-3914 is classified as a high severity vulnerability due to the risk of remote exploitation.
How do I fix CVE-2018-3914?
To address CVE-2018-3914, upgrade the Samsung SmartThings Hub STH-ETH-250 firmware to a version later than 0.20.17.
Who is affected by CVE-2018-3914?
CVE-2018-3914 affects users of the Samsung SmartThings Hub STH-ETH-250 running firmware version 0.20.17.
What type of vulnerability is CVE-2018-3914?
CVE-2018-3914 is a stack-based buffer overflow vulnerability that occurs during the retrieval of database fields.
Can exploitation of CVE-2018-3914 lead to complete system takeover?
Yes, successful exploitation of CVE-2018-3914 could allow an attacker to execute arbitrary code on the affected device.