Vulnerability Details CVE-2018-3912
On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process insecurely extracts the fields from the "shard" table of its SQLite database, leading to a buffer overflow on the stack. The strcpy call overflows the destination buffer, which has a size of 128 bytes. An attacker can send an arbitrarily long "secretKey" value in order to exploit this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 36.7%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 6.9
Products affected by CVE-2018-3912
-
cpe:2.3:h:samsung:sth-eth-250:-
-
cpe:2.3:o:samsung:sth-eth-250_firmware:0.20.17