CVE-2014-3911: Samsung Ipolis Device Manager
High severity, CVSS 9.3. EPSS: 5.6% chance of exploitation in the next 30 days.
Samsung iPOLiS Device Manager before 1.8.7 allow remote attackers to execute arbitrary code via unspecified values to the (1) Start, (2) ChangeControlLocalName, (3) DeleteDeviceProfile, (4) FrameAdvanceReader, or other unknown method in the XNSSDKDEVICE.XnsSdkDeviceCtrlForIpInstaller.1 ActiveX control.
Affected products
- Samsung Ipolis Device Manager: up to and including 1.8.2
Published 2014-06-11. Last modified 2026-06-17.