CVE-2014-2388
Last modified
CVE-2014-2388 is a vulnerability of currently unknown severity. The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in Development Mode.. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in Development Mode.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Blackberry | Blackberry Os | <= 10.1.0.2354 |
| Blackberry | Q10 | All versions |
| Blackberry | Q5 | All versions |
| Blackberry | Z10 | All versions |
| Blackberry | Z30 | All versions |
References
- http://www.blackberry.com/btsc/KB36174Vendor Advisory
- http://www.blackberry.com/btsc/KB36174Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-2388?
How severe is CVE-2014-2388?
How do I fix CVE-2014-2388?
Are you affected by CVE-2014-2388?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
