Lucene search

K
cveTalosCVE-2018-3911
HistoryAug 23, 2018 - 10:29 p.m.

CVE-2018-3911

2018-08-2322:29:00
CWE-113
talos
web.nvd.nist.gov
43
cve-2018-3911
http header injection
samsung smartthings hub
sth-eth-250
firmware
vulnerability
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

44.5%

An exploitable HTTP header injection vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The hubCore process listens on port 39500 and relays any unauthenticated message to SmartThings’ remote servers, which insecurely handle JSON messages, leading to partially controlled requests generated toward the internal video-core process. An attacker can send an HTTP request to trigger this vulnerability.

Affected configurations

Nvd
Vulners
Node
samsungsth-eth-250_firmwareMatch0.20.17
AND
samsungsth-eth-250Match-
VendorProductVersionCPE
samsungsth-eth-250_firmware0.20.17cpe:2.3:o:samsung:sth-eth-250_firmware:0.20.17:*:*:*:*:*:*:*
samsungsth-eth-250-cpe:2.3:h:samsung:sth-eth-250:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Samsung",
    "vendor": "Samsung",
    "versions": [
      {
        "status": "affected",
        "version": "Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

44.5%