PT-2017-15710 · Samsung · Samsung Magician
Will Dormann
·
Published
2017-06-21
·
Updated
2019-10-09
·
CVE-2017-3218
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Samsung Magician versions prior to 5.0
Description
The issue concerns the failure to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.
Recommendations
For versions prior to 5.0, consider updating to version 5.0 or later to enable HTTPS and proper TLS certificate validation for software updates.
Fix
Insufficient Verification of Data Authenticity
Missing Encryption of Sensitive Data
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Samsung Magician