Arbitrary Command Injection
Affecting samsung-remote package, versions <1.3.5
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
samsung-remote is a Module for integration of Samsung SmartTV with your NodeJS application. Tested with Samsung D6000 TV.
Affected versions of this package are vulnerable to Arbitrary Command Injection due to not sanitizing the IP address argument, and subsequently passes it to child_process.exec()
.
Remediation
Uograde samsung-remote
to version 1.3.5 or higher.
References
CVSS Score
10.0
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeChanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- Credit
- Douglas Hall
- CWE
- CWE-264
- Snyk ID
- SNYK-JS-SAMSUNGREMOTE-72278
- Disclosed
- 02 Sep, 2018
- Published
- 05 Sep, 2018