Show plain JSON{"id": "CVE-2016-3128", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 6.4, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 4.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 8.2, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 4.2, "exploitabilityScore": 3.9}]}, "published": "2017-01-13T09:59:00.420", "references": [{"url": "http://support.blackberry.com/kb/articleDetail?articleNumber=000038913", "tags": ["Mitigation", "Vendor Advisory"], "source": "secure@blackberry.com"}, {"url": "http://www.securityfocus.com/bid/95624", "source": "secure@blackberry.com"}, {"url": "http://www.securitytracker.com/id/1037585", "source": "secure@blackberry.com"}, {"url": "http://support.blackberry.com/kb/articleDetail?articleNumber=000038913", "tags": ["Mitigation", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/95624", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securitytracker.com/id/1037585", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-254"}]}], "descriptions": [{"lang": "en", "value": "A spoofing vulnerability in the Core of BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to enroll an illegitimate device to the BES, gain access to device parameters for the BES, or send false information to the BES by gaining access to specific information about a device that was legitimately enrolled on the BES."}, {"lang": "es", "value": "Una vulnerabilidad de suplantaci\u00f3n en el Core de BlackBerry Enterprise Server (BES) 12 hasta la versi\u00f3n 12.5.2 permite a atacantes remotos registrar un dispositivo ileg\u00edtimo al BES, acceder a los par\u00e1metros del dispositivo para el BES o enviar informaci\u00f3n falsa al BES accediendo a Informaci\u00f3n espec\u00edfica sobre un dispositivo que se inscribi\u00f3 leg\u00edtimamente en el BES."}], "lastModified": "2024-11-21T02:49:26.040", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:blackberry:enterprise_service:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CBD8C766-8C91-440F-99F7-7526AA7FD2BD"}, {"criteria": "cpe:2.3:a:blackberry:enterprise_service:12.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6ED84DDD-A736-4990-AF43-B94974B04BAA"}, {"criteria": "cpe:2.3:a:blackberry:enterprise_service:12.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "29E309B5-5F9E-4D8D-8A0A-49F3EB2B31A7"}, {"criteria": "cpe:2.3:a:blackberry:enterprise_service:12.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0633AD14-B5CC-46EA-88EB-B39B1A32FB15"}, {"criteria": "cpe:2.3:a:blackberry:enterprise_service:12.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6247B841-45B7-4CCE-A189-3EBFC8AB2003"}, {"criteria": "cpe:2.3:a:blackberry:enterprise_service:12.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7DE5722D-E406-4EE1-B55A-15B6B36FCFDA"}, {"criteria": "cpe:2.3:a:blackberry:enterprise_service:12.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "33F4B47B-A4AB-42E1-BDB6-A027B79CB3B4"}, {"criteria": "cpe:2.3:a:blackberry:enterprise_service:12.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "42160112-F133-4377-9CBA-56B71AAF5678"}, {"criteria": "cpe:2.3:a:blackberry:enterprise_service:12.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EBE0CC41-33D3-4102-84E8-22E2C70AD604"}, {"criteria": "cpe:2.3:a:blackberry:enterprise_service:12.5.0a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A138FF65-4563-4B65-B581-632DA00FB9E6"}, {"criteria": "cpe:2.3:a:blackberry:enterprise_service:12.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A0DFB57A-A2BF-4DE5-A25B-91D91159189F"}, {"criteria": "cpe:2.3:a:blackberry:enterprise_service:12.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9576124A-433E-4CBC-944B-9C06D794F937"}], "operator": "OR"}]}], "sourceIdentifier": "secure@blackberry.com"}