CVE-2014-6611: Input Validation

Published Oct 25, 2014
·
Updated

The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and before 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/update requests, which allows user-assisted man-in-the-middle attackers to spoof servers and trigger the download of a crafted app by modifying the client-server data stream.

Affected Software

6 affected components
BlackBerry BlackBerry World<=5.1.0.52
BlackBerry BlackBerry OS=10.3.0
BlackBerry BlackBerry World<=5.0.0.262
BlackBerry BlackBerry OS=10.2.1
BlackBerry BlackBerry World<=5.0.0.261
BlackBerry BlackBerry OS=10.2.0

Event History

Oct 25, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2014-6611?

CVE-2014-6611 is considered to be a moderate severity vulnerability due to the potential for man-in-the-middle attacks.

2

How do I fix CVE-2014-6611?

To remediate CVE-2014-6611, update the BlackBerry World app to version 5.1.0.53 or higher and ensure your BlackBerry 10 OS is updated appropriately.

3

Which devices are affected by CVE-2014-6611?

CVE-2014-6611 affects BlackBerry devices running BlackBerry World app versions prior to 5.0.0.263 and specific OS versions including 10.2.0 and 10.2.1.

4

What types of attacks can CVE-2014-6611 facilitate?

CVE-2014-6611 can facilitate user-assisted man-in-the-middle attacks, allowing adversaries to spoof servers and potentially compromise user data.

5

Is there a workaround for CVE-2014-6611 until a fix is applied?

No specific workarounds are recommended for CVE-2014-6611; therefore, prompt updating of the vulnerable software is advised.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203