← Back

CVE-2014-6611

nvd nist
Published: Oct 25, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and before 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/update requests, which allows user-assisted man-in-the-middle attackers to spoof servers and trigger the download of a crafted app by modifying the client-server data stream.

Affected (6)

2 products
Blackberry World
Blackberry Os
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 5.1.0.52
Version 10.3.0
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 5.0.0.262
Version 10.2.1
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 5.0.0.261
Version 10.2.0

References (4)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.