Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-3128


A spoofing vulnerability in the Core of BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to enroll an illegitimate device to the BES, gain access to device parameters for the BES, or send false information to the BES by gaining access to specific information about a device that was legitimately enrolled on the BES.


Published

2017-01-13T09:59:00.420

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 8.2 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-254

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application blackberry enterprise_service 12.0.0 Yes
Application blackberry enterprise_service 12.0.1 Yes
Application blackberry enterprise_service 12.1.0 Yes
Application blackberry enterprise_service 12.2.0 Yes
Application blackberry enterprise_service 12.2.1 Yes
Application blackberry enterprise_service 12.3.0 Yes
Application blackberry enterprise_service 12.3.1 Yes
Application blackberry enterprise_service 12.4.0 Yes
Application blackberry enterprise_service 12.4.1 Yes
Application blackberry enterprise_service 12.5.0a Yes
Application blackberry enterprise_service 12.5.1 Yes
Application blackberry enterprise_service 12.5.2 Yes

References