Local Information Disclosure in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x
CVE-2014-2534
Currently unrated
Key Information:
- Vendor
Blackberry
- Status
- Vendor
- CVE Published:
- 18 March 2014
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2014-2534?
In BlackBerry's QNX Neutrino RTOS versions 6.4.x and 6.5.x, a flaw in the /sbin/pppoectl component enables local users to read sensitive data from 'bad parameter' error messages. This could potentially expose critical information, such as the root password hash located in /etc/shadow, leading to unauthorized access or further security implications. Administrators should ensure that their systems are updated and monitor for unusual access patterns to mitigate such risks.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
