Back to Database
Status published
High
CVE-2017-3218
Samsung Magician 5.0 fails to validate TLS certificates for HTTPS...
Vulnerability Description
Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-3218
Credits & Attribution
No credits recorded in the NVD database.
More from Samsung
View All →CVE-2025-2233
Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability
High
8.8
CVE-2024-32670
Exposure of Sensitive Information to an Unauthorized Actor in Samsung...
High
7
CVE-2022-1230
This vulnerability allows local attackers to execute arbitrary code on...
Low
3.9
CVE-2020-8899
Memory corruption in Quram library when decoding qmg can lead to RCE
Critical
10
CVE-2020-8860
This vulnerability allows remote attackers to execute arbitrary code on...
High
7.1
Affected Vendor
Samsung
View all reports →Affected Software
Magician
Vulnerable Versions:
<5.1
Timeline
Official Publish:
June 21st, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
MITRE ATT&CK TTPs
T1557
Adversary-in-the-Middle
Credential Access
T1040
Network Sniffing
Collection
T1552
Unsecured Credentials
Credential Access
T1071
Application Layer Protocol
Command and Control
T1565
Data Manipulation
Impact
T1005
Data from Local System
Collection
T1041
Exfiltration Over C2 Channel
Exfiltration
T1078
Valid Accounts
Persistence
T1530
Data from Cloud Storage
Collection