6.1

CVE-2014-2388

Exploit

The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in Development Mode.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BlackberryBlackberry Os Version <= 10.1.0.2354
BlackberryQ10 Version-
BlackberryQ5 Version-
BlackberryZ10 Version-
BlackberryZ30 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.492
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 6.5 6.9
AV:A/AC:L/Au:N/C:C/I:N/A:N