PT-2017-15710 · Samsung · Samsung Magician
Will Dormann
·
Publicado
2017-06-21
·
Atualizado
2019-10-09
·
CVE-2017-3218
CVSS v3.1
8.8
Alta
| Vetor | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Samsung Magician versions prior to 5.0
Description
The issue concerns the failure to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.
Recommendations
For versions prior to 5.0, consider updating to version 5.0 or later to enable HTTPS and proper TLS certificate validation for software updates.
Correção
Insufficient Verification of Data Authenticity
Missing Encryption of Sensitive Data
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Samsung Magician