PT-2017-8346 · Blackberry · Blackberry Enterprise Server
Published
2017-01-13
·
Updated
2017-01-20
·
CVE-2016-3128
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
BlackBerry Enterprise Server versions 12 through 12.5.2
Description
A spoofing issue in the Core of BlackBerry Enterprise Server allows remote attackers to enroll an illegitimate device, gain access to device parameters, or send false information by accessing specific details about a legitimately enrolled device.
Recommendations
For versions 12 through 12.5.2, update to a version that contains a fix for this issue to prevent remote attackers from exploiting the spoofing vulnerability.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blackberry Enterprise Server