Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-6611


The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and before 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/update requests, which allows user-assisted man-in-the-middle attackers to spoof servers and trigger the download of a crafted app by modifying the client-server data stream.


Published

2014-10-25T10:55:06.743

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application blackberry blackberry_world ≤ 5.1.0.52 Yes
Operating System blackberry blackberry_os 10.3.0 Yes
Application blackberry blackberry_world ≤ 5.0.0.262 Yes
Operating System blackberry blackberry_os 10.2.1 Yes
Application blackberry blackberry_world ≤ 5.0.0.261 Yes
Operating System blackberry blackberry_os 10.2.0 Yes

References