PT-2018-16319 · Google+1 · Google Breakpad+2

Published

2018-08-27

·

Updated

2022-04-19

·

CVE-2018-3927

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17
Description An information disclosure issue exists in the crash handler of the hubCore binary. When hubCore crashes, it uses Google Breakpad to record minidumps, which are then sent over an insecure HTTPS connection to the backtrace.io service. This leads to the exposure of sensitive data. An attacker can impersonate the remote backtrace.io server to trigger this issue.
Recommendations For Firmware version 0.20.17, consider restricting access to the hubCore binary until a secure connection method is implemented for sending minidumps to the backtrace.io service. As a temporary workaround, disabling the crash handler or limiting its functionality may help minimize the risk of sensitive data exposure.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-3927

Affected Products

Google Breakpad
Samsung Smartthings Hub
Hubcore