HTTP header injection in SmartThings Hub STH-ETH-250 - CVE-2018-3911
Published: July 30, 2018
Vulnerability identifier: #VU14091
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-3911
CWE-ID: CWE-113
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to inject HTTP header on the target system.
The weakness exists in the remote servers of Samsung SmartThings Hub due to the
The weakness exists in the remote servers of Samsung SmartThings Hub due to the
hubCore
process listens on port 39500 and relays any unauthenticated message to SmartThings' remote servers, which insecurely handle JSON messages. A remote attacker can send an HTTP request and cause partially controlled requests to be generated toward the internal video-core process.Affected software
SmartThings Hub STH-ETH-250
How to mitigate CVE-2018-3911
Install update from vendor's website.