BlackBerry Desktop Software < 6.0.1 Database Backup File Password Brute Force Weakness

low Nessus Plugin ID 51395

Synopsis

The remote Windows host contains a program that uses a weak password to encrypt data.

Description

The version of BlackBerry Desktop Software installed on the remote host is older than version 6.0.1. Such versions use a weak password to encrypt backup files, which makes it possible for a local user to decrypt backup files via a brute-force attack.

Solution

Upgrade to BlackBerry Desktop Software 6.0.1 or later.

See Also

https://salesforce.services.blackberry.com/kbredirect/KB24764

Plugin Details

Severity: Low

ID: 51395

File Name: blackberry_desktop_software_6_0_1.nasl

Version: 1.7

Type: local

Agent: windows

Family: Windows

Published: 12/30/2010

Updated: 11/15/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.2

CVSS v2

Risk Factor: Low

Base Score: 2.1

Temporal Score: 1.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

Required KB Items: SMB/Registry/Enumerated

Exploit Ease: No known exploits are available

Patch Publication Date: 12/15/2010

Vulnerability Publication Date: 12/15/2010

Reference Information

CVE: CVE-2010-2603

BID: 45434

Secunia: 42657