PT-2018-16319 · Google+1 · Google Breakpad+2
Published
2018-08-27
·
Updated
2022-04-19
·
CVE-2018-3927
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17
Description
An information disclosure issue exists in the crash handler of the hubCore binary. When hubCore crashes, it uses Google Breakpad to record minidumps, which are then sent over an insecure HTTPS connection to the backtrace.io service. This leads to the exposure of sensitive data. An attacker can impersonate the remote backtrace.io server to trigger this issue.
Recommendations
For Firmware version 0.20.17, consider restricting access to the hubCore binary until a secure connection method is implemented for sending minidumps to the backtrace.io service. As a temporary workaround, disabling the crash handler or limiting its functionality may help minimize the risk of sensitive data exposure.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Breakpad
Samsung Smartthings Hub
Hubcore