CVE-2014-2388: Medium severity blackberry os vulnerability
The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in Development Mode.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2388?
CVE-2014-2388 is considered a medium severity vulnerability that can lead to unauthorized access to sensitive files.
How do I fix CVE-2014-2388?
To fix CVE-2014-2388, update BlackBerry OS to the latest version that addresses this vulnerability.
Which devices are affected by CVE-2014-2388?
CVE-2014-2388 affects BlackBerry Q5, Q10, Z10, and Z30 devices running BlackBerry OS versions up to 10.1.0.2354.
What type of attack does CVE-2014-2388 expose?
CVE-2014-2388 exposes devices to risk from context-dependent attackers who can exploit SMB filesystem access without a password.
Does CVE-2014-2388 require physical access to the device?
No, CVE-2014-2388 can be exploited over a Wi-Fi network, making physical access unnecessary.