CVE-2017-3218

HIGH

Samsung Magician - Improper Certificate Validation

Title source: rule
STIX 2.1

Description

Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99081
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
https://www.kb.cert.org/vuls/id/846320

Scores

CVSS v3 8.8
EPSS 0.0002
EPSS Percentile 4.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-295 CWE-345 CWE-311
Status published
Products (2)
samsung/magician 5.0
Samsung/Magician <5.1
Published Jun 21, 2017
Tracked Since Feb 18, 2026