Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-3916

Опубликовано: 28 авг. 2018
Источник: nvd
CVSS3: 7.5
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 136 bytes. An attacker can send an arbitrarily long 'directory' value in order to exploit this vulnerability. An attacker can send an HTTP request to trigger this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:samsung:sth-eth-250_firmware:0.20.17:*:*:*:*:*:*:*
cpe:2.3:h:samsung:sth-eth-250:-:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00161
Низкий

7.5 High

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 136 bytes. An attacker can send an arbitrarily long 'directory' value in order to exploit this vulnerability. An attacker can send an HTTP request to trigger this vulnerability.

EPSS

Процентиль: 37%
0.00161
Низкий

7.5 High

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-787