CVE-2017-3218

HIGH

Samsung Magician < 5.1 - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99081
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
https://www.kb.cert.org/vuls/id/846320

Scores

CVSS v3 8.8
EPSS 0.0034
EPSS Percentile 26.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-295 CWE-311 CWE-345
Status published
Products (2)
samsung/magician 5.0
Samsung/Magician <5.1
Published Jun 21, 2017
Tracked Since Feb 18, 2026