Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Data_management_server_firmware | Samsung | 2.0.0 (including) | 2.3.13.1 (excluding) |
Data_management_server_firmware | Samsung | 2.5.0.17 (including) | 2.6.14.1 (excluding) |
Data_management_server_firmware | Samsung | 2.7.0.15 (including) | 2.9.3.6 (excluding) |