Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.
References
Link | Resource |
---|---|
https://www.kb.cert.org/vuls/id/846320 | Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/99081 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2017-06-21 13:29
Updated : 2019-10-09 16:27
NVD link : CVE-2017-3218
Mitre link : CVE-2017-3218
JSON object : View
CWE
CWE-345
Insufficient Verification of Data Authenticity
Products Affected
samsung
- magician