CVE-2018-3915: Buffer Overflow
An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 64 bytes. An attacker can send an arbitrarily long "bucket" value in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3915?
CVE-2018-3915 is considered a critical vulnerability due to its potential to allow remote code execution via a stack-based buffer overflow.
How do I fix CVE-2018-3915?
To fix CVE-2018-3915, update the Samsung SmartThings Hub to the latest firmware version beyond 0.20.17.
What software is affected by CVE-2018-3915?
The affected software for CVE-2018-3915 is the Samsung SmartThings Hub STH-ETH-250 running firmware version 0.20.17.
Can CVE-2018-3915 be exploited remotely?
Yes, CVE-2018-3915 can be exploited remotely, allowing an attacker to execute arbitrary code.
What type of vulnerability is CVE-2018-3915?
CVE-2018-3915 is classified as a stack-based buffer overflow vulnerability.