CVE-2014-2388
Summary
| CVE | CVE-2014-2388 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-08-18 11:15:25 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in Development Mode. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
NoneAvailability
NoneAV:A/AC:L/Au:N/C:C/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Blackberry | Blackberry Os | All | All | All | All |
| Hardware | Blackberry | Q10 | - | All | All | All |
| Hardware | Blackberry | Q5 | - | All | All | All |
| Hardware | Blackberry | Z10 | - | All | All | All |
| Hardware | Blackberry | Z30 | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BlackBerry Z10 Authentication Bypass ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Security Advisory SA60156 - BlackBerry OS File Sharing Authentication Bypass Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| BlackBerry Z10 CVE-2014-2388 Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www.modzero.ch/advisories/MZ-13-04-Blackberry_Z10-File-Exchange-Authenticati... | af854a3a-2127-422b-91ae-364da2661108 | www.modzero.ch | Exploit |
| KB36174-BSRT-2014-006 Vulnerability in file sharing service affects BlackBerry Z10, BlackBerry Z30, BlackBerry Q10, and BlackBerry Q5 smartphones | af854a3a-2127-422b-91ae-364da2661108 | www.blackberry.com | Vendor Advisory |
| BlackBerry Z10 Authentication Bypass ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.