Stack-based buffer overflow in SmartThings Hub STH-ETH-250 - CVE-2018-3912
Published: July 30, 2018
Vulnerability identifier: #VU14092
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2018-3912
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Samsung
Affected software:
SmartThings Hub STH-ETH-250
SmartThings Hub STH-ETH-250
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists in the retrieval of database fields in the
The weakness exists in the retrieval of database fields in the
video-core HTTP server of the Samsung SmartThings Hub due to insecure extracting of the fields from the "shard" table of its SQLite database. A remote attacker can send an HTTP request, trigger stack-based buffer overflow and execute arbitrary code with elevated privileges.
How to mitigate CVE-2018-3912
Install update from vendor's website.