CVE-2014-2388
Summary
| CVE | CVE-2014-2388 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-08-18 11:15:00 UTC |
| Updated | 2018-10-09 19:43:00 UTC |
| Description | The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in Development Mode. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Blackberry | Blackberry Os | All | All | All | All |
| Hardware | Blackberry | Q10 | - | All | All | All |
| Hardware | Blackberry | Q10 | - | All | All | All |
| Hardware | Blackberry | Q5 | - | All | All | All |
| Hardware | Blackberry | Q5 | - | All | All | All |
| Hardware | Blackberry | Z10 | - | All | All | All |
| Hardware | Blackberry | Z10 | - | All | All | All |
| Hardware | Blackberry | Z30 | - | All | All | All |
| Hardware | Blackberry | Z30 | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BlackBerry Z10 CVE-2014-2388 Authentication Bypass Vulnerability | BID | www.securityfocus.com | |
| Security Advisory SA60156 - BlackBerry OS File Sharing Authentication Bypass Vulnerability - Secunia | SECUNIA | secunia.com | |
| BlackBerry Z10 Authentication Bypass ≈ Packet Storm | MISC | packetstormsecurity.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| KB36174-BSRT-2014-006 Vulnerability in file sharing service affects BlackBerry Z10, BlackBerry Z30, BlackBerry Q10, and BlackBerry Q5 smartphones | CONFIRM | www.blackberry.com | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| BlackBerry Z10 Authentication Bypass ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit |
| www.modzero.ch/advisories/MZ-13-04-Blackberry_Z10-File-Exchange-Authenticati... | MISC | www.modzero.ch | Exploit |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.