PT-2017-15710 · Samsung · Samsung Magician

Will Dormann

·

Publicado

2017-06-21

·

Atualizado

2019-10-09

·

CVE-2017-3218

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Samsung Magician versions prior to 5.0
Description The issue concerns the failure to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.
Recommendations For versions prior to 5.0, consider updating to version 5.0 or later to enable HTTPS and proper TLS certificate validation for software updates.

Correção

Insufficient Verification of Data Authenticity

Missing Encryption of Sensitive Data

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-3218

Produtos afetados

Samsung Magician