ID

VAR-201501-0783


TITLE

Multiple BlackBerry Products Local Security Bypass Vulnerabilities

Trust: 0.6

sources: CNVD: CNVD-2015-00290

DESCRIPTION

BlackBerry is a mobile phone that supports basic functions such as multiple mail systems, multiple format attachments, mail filtering, and remote clearing of email data. Multiple BlackBerry products have security vulnerabilities that allow local attackers to bypass security restrictions, perform unauthorized operations, etc. through the USB port

Trust: 0.81

sources: CNVD: CNVD-2015-00290 // BID: 71893

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-00290

AFFECTED PRODUCTS

vendor:blackberrymodel:blackberryscope: - version: -

Trust: 0.6

vendor:rimmodel:blackberryscope:eqversion:7.1

Trust: 0.3

vendor:blackberrymodel:torchscope:eqversion:9860

Trust: 0.3

vendor:blackberrymodel:torchscope:eqversion:9850

Trust: 0.3

vendor:blackberrymodel:torchscope:eqversion:9810

Trust: 0.3

vendor:blackberrymodel:stylescope:eqversion:9670

Trust: 0.3

vendor:blackberrymodel:storm2scope:eqversion:9550

Trust: 0.3

vendor:blackberrymodel:stormscope:eqversion:9530

Trust: 0.3

vendor:blackberrymodel:stormscope:eqversion:9500

Trust: 0.3

vendor:blackberrymodel:pearl flipscope:eqversion:8230

Trust: 0.3

vendor:blackberrymodel:pearlscope:eqversion:8230

Trust: 0.3

vendor:blackberrymodel:pearl 8130mscope: - version: -

Trust: 0.3

vendor:blackberrymodel:curvescope:eqversion:9370

Trust: 0.3

vendor:blackberrymodel:curvescope:eqversion:9350

Trust: 0.3

vendor:blackberrymodel:curvescope:eqversion:9330

Trust: 0.3

vendor:blackberrymodel:curvescope:eqversion:9310

Trust: 0.3

vendor:blackberrymodel:curvescope:eqversion:8530

Trust: 0.3

vendor:blackberrymodel:boldscope:eqversion:9930

Trust: 0.3

vendor:blackberrymodel:boldscope:eqversion:9900

Trust: 0.3

vendor:blackberrymodel:boldscope:eqversion:9650

Trust: 0.3

sources: CNVD: CNVD-2015-00290 // BID: 71893

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2015-00290
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2015-00290
severity: MEDIUM
baseScore: 4.4
vectorString: AV:L/AC:M/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2015-00290

THREAT TYPE

local

Trust: 0.3

sources: BID: 71893

TYPE

Design Error

Trust: 0.3

sources: BID: 71893

PATCH

title:Patches for local security bypass vulnerabilities in multiple BlackBerry productsurl:https://www.cnvd.org.cn/patchinfo/show/53934

Trust: 0.6

sources: CNVD: CNVD-2015-00290

EXTERNAL IDS

db:BIDid:71893

Trust: 0.9

db:CNVDid:CNVD-2015-00290

Trust: 0.6

sources: CNVD: CNVD-2015-00290 // BID: 71893

REFERENCES

url:http://www.securityfocus.com/bid/71893/

Trust: 0.6

url:http://us.blackberry.com/

Trust: 0.3

url:http://btsc.webapps.blackberry.com/btsc/viewdocument.do;jsessionid=ffee88c44e68b677713a75741a6988b8?nocount=true&externalid=kb36557&sliceid=1&cmd=&forward=nonthreadedkc&command=show&kcid=kb36557&viewe

Trust: 0.3

sources: CNVD: CNVD-2015-00290 // BID: 71893

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 71893

SOURCES

db:CNVDid:CNVD-2015-00290
db:BIDid:71893

LAST UPDATE DATE

2022-05-17T02:01:11.173000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-00290date:2015-01-14T00:00:00
db:BIDid:71893date:2014-12-26T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-00290date:2015-01-14T00:00:00
db:BIDid:71893date:2014-12-26T00:00:00