PT-2018-16319 · Google+1 · Google Breakpad+2
Publicado
2018-08-27
·
Atualizado
2022-04-19
·
CVE-2018-3927
CVSS v3.1
6.8
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17
Description
An information disclosure issue exists in the crash handler of the hubCore binary. When hubCore crashes, it uses Google Breakpad to record minidumps, which are then sent over an insecure HTTPS connection to the backtrace.io service. This leads to the exposure of sensitive data. An attacker can impersonate the remote backtrace.io server to trigger this issue.
Recommendations
For Firmware version 0.20.17, consider restricting access to the hubCore binary until a secure connection method is implemented for sending minidumps to the backtrace.io service. As a temporary workaround, disabling the crash handler or limiting its functionality may help minimize the risk of sensitive data exposure.
Exploit
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Google Breakpad
Samsung Smartthings Hub
Hubcore