Vulnerabilidades em Samsung

56 resultados
Análise Vexday

Com 56 CVEs catalogadas, o perfil Samsung apresenta taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada confirmada no CISA KEV —, o que sugere pressão operacional imediata relativamente contida. Ainda assim, 24 vulnerabilidades de severidade crítica representam uma superfície de ataque expressiva que exige atenção contínua de equipes de patch management. A falha mais prevalente é CWE-20 (validação inadequada de entrada), padrão que tende a viabilizar explorações encadeadas quando não corrigido sistematicamente. O maior EPSS observado (0,0593) pertence a CVE-2019-6742, indicando probabilidade de exploração ainda moderada para essa CVE específica; a existência de uma PoC pública no conjunto reforça a necessidade de priorizar a remediação das entradas críticas mesmo na ausência de exploração ativa confirmada.

CVE-2018-3863CRITICALOn Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extracts fields from a userEPSS 1.7%CVE-2019-6335A potential security vulnerability has been identified with Samsung Laser Printers. This vulnerability could potentially be exploited to creEPSS 1.6%CVE-2018-3879HIGHAn exploitable JSON injection vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETHEPSS 1.6%CVE-2018-3878CRITICALMultiple exploitable buffer overflow vulnerabilities exist in the credentials handler of video-core's HTTP server of Samsung SmartThings HubEPSS 1.5%CVE-2018-3897CRITICALAn exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings HEPSS 1.5%CVE-2018-3875CRITICALAn exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETEPSS 1.5%CVE-2018-3866CRITICALAn exploitable buffer overflow vulnerability exists in the samsungWifiScan handler of video-core's HTTP server of Samsung SmartThings Hub STEPSS 1.5%CVE-2018-3896CRITICALAn exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings HEPSS 1.5%CVE-2018-3905HIGHAn exploitable buffer overflow vulnerability exists in the camera "create" feature of video-core's HTTP server of Samsung SmartThings Hub STEPSS 1.5%CVE-2018-3925HIGHAn exploitable buffer overflow vulnerability exists in the remote video-host communication of video-core's HTTP server of Samsung SmartThingEPSS 1.5%CVE-2018-11614This vulnerability allows remote attackers to escalate privileges on vulnerable installations of Samsung Members Fixed in version 2.4.25. AnEPSS 1.3%CVE-2018-3908CRITICALAn exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250-Firmware versiEPSS 1.3%CVE-2018-3880HIGHAn exploitable stack-based buffer overflow vulnerability exists in the database 'find-by-cameraId' functionality of video-core's HTTP serverEPSS 1.2%CVE-2018-3911HIGHAn exploitable HTTP header injection vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.EPSS 1.2%CVE-2018-3927MEDIUMAn exploitable information disclosure vulnerability exists in the crash handler of the hubCore binary of the Samsung SmartThings Hub STH-ETHEPSS 1.1%CVE-2018-3918MEDIUMAn exploitable vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The hubCore proEPSS 1.0%CVE-2018-3919HIGHAn exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in video-core's HTTP server of Samsung SEPSS 0.9%CVE-2018-3917HIGHOn Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process insecurely extracts the fields from theEPSS 0.9%CVE-2020-9061Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10EPSS 0.7%CVE-2025-2233HIGHSamsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass VulnerabilityEPSS 0.7%