HTTP: Samsung iPOLiS Device Manager Unsafe ActiveX Control

This signature detects attempts to use unsafe ActiveX controls in the Samsung iPOLiS Device Manager. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitrary code via a long string in the first argument to the (1) ReadConfigValue or (2) WriteConfigValue function.

Affected Products

Samsung ipolis_device_manager

References

BugTraq: 67823

CVE: CVE-2014-3912

Short Name
HTTP:STC:ACTIVEX:SAM-DVMR
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX CVE-2014-3912 CVE-2015-0555 Control Device Manager Samsung Unsafe bid:67823 iPOLiS
Release Date
08/06/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3813
False Positive
Unknown
Vendors

Samsung

CVSS Score

9.3

6.8

Found a potential security threat?