LiveActive security incident?Get immediate response
CVE Record

CVE-2018-3897: An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTT...

An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub with Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. The strncpy call overflows the destination buffer, which has a size of 52 bytes. An attacker can send an arbitrarily long "callbackUrl" value in order to exploit this vulnerability.

CriticalCVSS 9.9Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

A flaw in Samsung SmartThings Hub firmware 0.20.17 can let a low-privileged network attacker compromise the hub through its video handling service. Because a hub can bridge smart devices and local networks, affected deployments should treat this as urgent until firmware and exposure are confirmed.

Executive priority

Prioritize remediation for any affected hubs on business or sensitive home-office networks. The technical impact is critical, but business urgency depends on whether firmware 0.20.17 devices are still deployed and reachable.

Technical view

The video-core HTTP server’s /cameras/XXXX/clips handler copies a user-controlled JSON callbackUrl into a 52-byte stack buffer, causing a buffer overflow. The published CVSS 3.0 score is 9.9 with network attack vector, low privileges required, no user interaction, and high confidentiality, integrity, and availability impact.

Likely exposure

Exposure is limited to Samsung SmartThings Hub STH-ETH-250 devices running firmware 0.20.17 where the affected video-core HTTP service is reachable by a low-privileged attacker. The sources do not identify other firmware versions or products as affected.

Exploitation context

The CVE record describes the issue as exploitable, but the provided sources do not show CISA KEV listing or confirmed active exploitation. The attack requires network reachability and low privileges; no user interaction is required.

Researcher notes

Evidence is strongest for Samsung SmartThings Hub STH-ETH-250 firmware 0.20.17. The source bundle gives detailed root cause and CVSS data, but does not provide a named patch version, workaround, public exploit status, or broader affected-version range.

Mitigation direction

  • Identify any Samsung SmartThings Hub STH-ETH-250 devices in use.
  • Confirm whether firmware version 0.20.17 is present.
  • Check Samsung or SmartThings guidance for fixed firmware or supported replacement options.
  • Restrict network access to the hub and its management services.
  • Remove or isolate affected hubs if vendor remediation is unavailable.

Validation and detection

  • Inventory hub model, firmware version, and deployment location.
  • Verify who can reach the hub’s HTTP services over the network.
  • Review logs or monitoring for unexpected video-core crashes or restarts.
  • Confirm compensating controls block untrusted network access.
  • Track vendor advisories for remediation status before closing the finding.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-3897 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.9 (3.0)
Known Exploited
No
Published

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.9CVSS 3.0CriticalCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H3.16Primary CVE score

Vulnerability scoring details

Base CVSS 3.0 score

9.9Critical
CVSS 3.0 vector shape for CVE-2018-3897Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
SamsungSmartThings Hub STH-ETH-250Firmware version 0.20.17Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.