#VU14097 Stack-based buffer overflow in SmartThings Hub STH-ETH-250 - CVE-2018-3917
Published: July 30, 2018
Vulnerability identifier: #VU14097
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2018-3917
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
SmartThings Hub STH-ETH-250
SmartThings Hub STH-ETH-250
Software vendor:
Samsung
Samsung
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists in the retrieval of database fields in the
The weakness exists in the retrieval of database fields in the
video-core HTTP server of the Samsung SmartThings Hub due to insecure extracting of the fields from the "shard" table of its SQLite database. A remote attacker can send an HTTP request, trigger stack-based buffer overflow and execute arbitrary code with elevated privileges.
Remediation
Install update from vendor's website.