Information Disclosure in BlackBerry Enterprise Server Management Console
CVE-2016-3130

8.1HIGH

Key Information:

Vendor

Blackberry

Vendor
CVE Published:
13 January 2017

What is CVE-2016-3130?

An information disclosure vulnerability exists in the Core and Management Console of BlackBerry Enterprise Server versions 12 through 12.5.2. This flaw enables remote attackers to capture sensitive local or domain credentials of user or administrator accounts by intercepting and analyzing the network traffic during login attempts. Unauthorized access to these credentials can lead to significant security breaches within an organization's network, underscoring the necessity for securing data transmission protocols.

Affected Version(s)

BES12 through 12.5.2 BES12 versions through 12.5.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.