Vulnerability Details CVE-2018-3856
An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The device incorrectly handles spaces in the URL field, leading to an arbitrary operating system command injection. An attacker can send a series of HTTP requests to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 81.0%
CVSS Severity
CVSS v3 Score 9.9
CVSS v2 Score 9.0
Products affected by CVE-2018-3856
-
cpe:2.3:h:samsung:sth-eth-250:-
-
cpe:2.3:o:samsung:sth-eth-250_firmware:0.20.17