PT-2017-15710 · Samsung · Samsung Magician

Will Dormann

·

Published

2017-06-21

·

Updated

2019-10-09

·

CVE-2017-3218

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Samsung Magician versions prior to 5.0
Description The issue concerns the failure to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.
Recommendations For versions prior to 5.0, consider updating to version 5.0 or later to enable HTTPS and proper TLS certificate validation for software updates.

Fix

Insufficient Verification of Data Authenticity

Missing Encryption of Sensitive Data

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-3218

Affected Products

Samsung Magician