CVE-2014-2388
Last modified
CVE-2014-2388 is a vulnerability of currently unknown severity. The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in Development Mode.. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in Development Mode.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Blackberry | Blackberry Os | <= 10.1.0.2354 |
| Blackberry | Q10 | All versions |
| Blackberry | Q5 | All versions |
| Blackberry | Z10 | All versions |
| Blackberry | Z30 | All versions |
References
- http://www.blackberry.com/btsc/KB36174Vendor Advisory
- http://www.blackberry.com/btsc/KB36174Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-2388?
How severe is CVE-2014-2388?
How do I fix CVE-2014-2388?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-2382The DfDiskLo.sys driver in Faronics Deep Freeze Standard and…
- CVE-2014-2383dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is…
- CVE-2014-2384vmx86.sys in VMware Workstation 10.0.1 build 1379776 and VMw…
- CVE-2014-2385Multiple cross-site scripting (XSS) vulnerabilities in the w…
- CVE-2014-2386Multiple off-by-one errors in Icinga, possibly 1.10.2 and ea…
- CVE-2014-2387Pen 0.18.0 has Insecure Temporary File Creation vulnerabilit…4.4
- CVE-2014-2389Stack-based buffer overflow in a certain decryption function…
- CVE-2014-2390Cross-site request forgery (CSRF) vulnerability in the User …
- CVE-2014-2391The password recovery service in Open-Xchange AppSuite befor…
- CVE-2014-2392The E-Mail autoconfiguration feature in Open-Xchange AppSuit…
- CVE-2014-2393Cross-site scripting (XSS) vulnerability in Open-Xchange App…
- CVE-2014-2397Unspecified vulnerability in Oracle Java SE 7u51 and 8, and …
Are you affected by CVE-2014-2388?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
