Vulnerability Description
An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly handles pipelined HTTP requests, which allows successive requests to overwrite the previously parsed HTTP method, 'onmessagecomplete' callback. An attacker can send an HTTP request to trigger this vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Sth-Eth-250 Firmware | 0.20.17 |
| Samsung | Sth-Eth-250 | - |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0577ExploitThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0577ExploitThird Party Advisory
FAQ
What is CVE-2018-3909?
CVE-2018-3909 is a vulnerability with a CVSS score of 8.6 (HIGH). An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly handles pip...
How severe is CVE-2018-3909?
CVE-2018-3909 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-3909?
Check the references section above for vendor advisories and patch information. Affected products include: Samsung Sth-Eth-250 Firmware, Samsung Sth-Eth-250.