4.3
CVSSv2

CVE-2014-6611

Published: 25/10/2014 Updated: 28/01/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The BlackBerry World app prior to 5.0.0.262 on BlackBerry 10 OS 10.2.0, prior to 5.0.0.263 on BlackBerry 10 OS 10.2.1, and prior to 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/update requests, which allows user-assisted man-in-the-middle malicious users to spoof servers and trigger the download of a crafted app by modifying the client-server data stream.

Vulnerable Product Search on Vulmon Subscribe to Product

blackberry blackberry_world

blackberry blackberry_os 10.3.0

blackberry blackberry_os 10.2.1

blackberry blackberry_os 10.2.0