CVE-2014-2388

T

he Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in Development Mode.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:blackberry:blackberry_os:*:*:*:*:*:*:*:*
OR cpe:2.3:h:blackberry:q10:-:*:*:*:*:*:*:*
cpe:2.3:h:blackberry:q5:-:*:*:*:*:*:*:*
cpe:2.3:h:blackberry:z10:-:*:*:*:*:*:*:*
cpe:2.3:h:blackberry:z30:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:06

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/127850 - Exploit () http://packetstormsecurity.com/files/127850 - Exploit
References () http://packetstormsecurity.com/files/127850/BlackBerry-Z10-Authentication-Bypass.html - () http://packetstormsecurity.com/files/127850/BlackBerry-Z10-Authentication-Bypass.html -
References () http://secunia.com/advisories/60156 - () http://secunia.com/advisories/60156 -
References () http://www.blackberry.com/btsc/KB36174 - Vendor Advisory () http://www.blackberry.com/btsc/KB36174 - Vendor Advisory
References () http://www.modzero.ch/advisories/MZ-13-04-Blackberry_Z10-File-Exchange-Authentication-By-Pass.txt - Exploit () http://www.modzero.ch/advisories/MZ-13-04-Blackberry_Z10-File-Exchange-Authentication-By-Pass.txt - Exploit
References () http://www.securityfocus.com/archive/1/533118/100/0/threaded - () http://www.securityfocus.com/archive/1/533118/100/0/threaded -
References () http://www.securityfocus.com/bid/69217 - () http://www.securityfocus.com/bid/69217 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/95262 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/95262 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/95263 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/95263 -

Information

Published : 2014-08-18 11:15

Updated : 2025-04-12 10:46


NVD link : CVE-2014-2388

Mitre link : CVE-2014-2388

CVE.ORG link : CVE-2014-2388


JSON object : View

Products Affected
CWE
CWE-264

Permissions, Privileges, and Access Controls