#VU14098 Stack-based buffer overflow in SmartThings Hub STH-ETH-250 - CVE-2018-3919
Published: July 30, 2018
Vulnerability identifier: #VU14098
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2018-3919
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
SmartThings Hub STH-ETH-250
SmartThings Hub STH-ETH-250
Software vendor:
Samsung
Samsung
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists in the retrieval of database fields in
The weakness exists in the retrieval of database fields in
video-core's HTTP server of Samsung SmartThings Hub due to insecure extracting of the fields from the "clips" table of its SQLite database. A remote attacker can send an HTTP request, trigger stack-based buffer overflow and execute arbitrary code with elevated privileges.
Remediation
Install update from vendor's website.