Home
HIGH: 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
2.0.0 (custom) before 2.3.13.1
affected
2.5.0.17 (custom) before 2.6.14.1
affected
2.7.0.15 (custom) before 2.9.3.6
affected
Description
Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
2.0.0 (custom) before 2.3.13.1
2.5.0.17 (custom) before 2.6.14.1
2.7.0.15 (custom) before 2.9.3.6
Credits
Noam Moshe of Claroty Team82
References
security.samsungda.com/securityUpdates.html