Vulnerability Description
The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in Development Mode.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Blackberry | Blackberry Os | <= 10.1.0.2354 |
| Blackberry | Q10 | - |
| Blackberry | Q5 | - |
| Blackberry | Z10 | - |
| Blackberry | Z30 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/127850Exploit
- http://packetstormsecurity.com/files/127850/BlackBerry-Z10-Authentication-Bypass
- http://secunia.com/advisories/60156
- http://www.blackberry.com/btsc/KB36174Vendor Advisory
- http://www.modzero.ch/advisories/MZ-13-04-Blackberry_Z10-File-Exchange-AuthenticExploit
- http://www.securityfocus.com/archive/1/533118/100/0/threaded
- http://www.securityfocus.com/bid/69217
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95262
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95263
- http://packetstormsecurity.com/files/127850Exploit
- http://packetstormsecurity.com/files/127850/BlackBerry-Z10-Authentication-Bypass
- http://secunia.com/advisories/60156
- http://www.blackberry.com/btsc/KB36174Vendor Advisory
- http://www.modzero.ch/advisories/MZ-13-04-Blackberry_Z10-File-Exchange-AuthenticExploit
- http://www.securityfocus.com/archive/1/533118/100/0/threaded
FAQ
What is CVE-2014-2388?
CVE-2014-2388 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-depen...
How severe is CVE-2014-2388?
CVE-2014-2388 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-2388?
Check the references section above for vendor advisories and patch information. Affected products include: Blackberry Blackberry Os, Blackberry Q10, Blackberry Q5, Blackberry Z10, Blackberry Z30.