CVE-2016-3128
Summary
| CVE | CVE-2016-3128 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-01-13 09:59:00 UTC |
| Updated | 2017-01-20 02:59:00 UTC |
| Description | A spoofing vulnerability in the Core of BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to enroll an illegitimate device to the BES, gain access to device parameters for the BES, or send false information to the BES by gaining access to specific information about a device that was legitimately enrolled on the BES. |
Risk And Classification
Problem Types: CWE-254
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Blackberry | Enterprise Service | 12.0.0 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.0.1 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.1.0 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.2.0 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.2.1 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.3.0 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.3.1 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.4.0 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.4.1 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.5.0a | All | All | All |
| Application | Blackberry | Enterprise Service | 12.5.1 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.5.2 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.0.0 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.0.1 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.1.0 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.2.0 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.2.1 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.3.0 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.3.1 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.4.0 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.4.1 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.5.0a | All | All | All |
| Application | Blackberry | Enterprise Service | 12.5.1 | All | All | All |
| Application | Blackberry | Enterprise Service | 12.5.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BSRT-2017-001 Vulnerability in BES Core impacts BES12 | CONFIRM | support.blackberry.com | Mitigation, Vendor Advisory |
| BlackBerry Enterprise Server Unspecified Flaw Lets Remote Users Spoof Enrolled Devices - SecurityTracker | SECTRACK | www.securitytracker.com | |
| BlackBerry Enterprise Server CVE-2016-3128 Spoofing Vulnerability | BID | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.