Lucene search

K
cve[email protected]CVE-2014-2388
HistoryAug 18, 2014 - 11:15 a.m.

CVE-2014-2388

2014-08-1811:15:25
CWE-264
web.nvd.nist.gov
29
cve-2014-2388
blackberry os
storage and access service
smb filesystem
password requirement
context-dependent attackers
arbitrary files
nvd

6.1 Medium

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:L/Au:N/C:C/I:N/A:N

6.8 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

61.2%

The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in Development Mode.

Affected configurations

NVD
Node
blackberryblackberry_osRange10.1.0.2354
AND
blackberryq10Match-
OR
blackberryq5Match-
OR
blackberryz10Match-
OR
blackberryz30Match-

6.1 Medium

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:L/Au:N/C:C/I:N/A:N

6.8 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

61.2%