CVE-2014-6611: Input Validation
The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and before 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/update requests, which allows user-assisted man-in-the-middle attackers to spoof servers and trigger the download of a crafted app by modifying the client-server data stream.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6611?
CVE-2014-6611 is considered to be a moderate severity vulnerability due to the potential for man-in-the-middle attacks.
How do I fix CVE-2014-6611?
To remediate CVE-2014-6611, update the BlackBerry World app to version 5.1.0.53 or higher and ensure your BlackBerry 10 OS is updated appropriately.
Which devices are affected by CVE-2014-6611?
CVE-2014-6611 affects BlackBerry devices running BlackBerry World app versions prior to 5.0.0.263 and specific OS versions including 10.2.0 and 10.2.1.
What types of attacks can CVE-2014-6611 facilitate?
CVE-2014-6611 can facilitate user-assisted man-in-the-middle attacks, allowing adversaries to spoof servers and potentially compromise user data.
Is there a workaround for CVE-2014-6611 until a fix is applied?
No specific workarounds are recommended for CVE-2014-6611; therefore, prompt updating of the vulnerable software is advised.