Local Information Disclosure in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x
CVE-2014-2534

Currently unrated

Key Information:

Vendor

Blackberry

Vendor
CVE Published:
18 March 2014

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2014-2534?

In BlackBerry's QNX Neutrino RTOS versions 6.4.x and 6.5.x, a flaw in the /sbin/pppoectl component enables local users to read sensitive data from 'bad parameter' error messages. This could potentially expose critical information, such as the root password hash located in /etc/shadow, leading to unauthorized access or further security implications. Administrators should ensure that their systems are updated and monitor for unusual access patterns to mitigate such risks.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.