| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.801523 |
| Category: | Brute force attacks |
| Title: | BlackBerry Desktop Software Security Bypass Vulnerability |
| Summary: | Copyright (c) 2010 Greenbone Networks GmbH |
| Description: | Overview: This host has BlackBerry Desktop Software installed and is prone to security bypass vulnerability. Vulnerability Insight: The flaw is cused due to error in 'offline backup' mechanism in 'Research In Motion' (RIM), which uses single-iteration 'PBKDF2', which makes it easier for local users to decrypt a '.ipd' file via a brute-force attack. Impact: Successful exploitation could allow attackers to steal or guess document's password via a brute force attacks. Impact Level: Application Affected Software/OS: BlackBerry Desktop Software version 6.0.0.43 and prior. Fix: No solution or patch is available as of 12th October, 2010. Information regarding this issue will be updated once the solution details are available. For updates refer to http://na.blackberry.com/eng/services/desktop/ References: http://it.slashdot.org/story/10/10/01/166226/ http://twitter.com/elcomsoft/statuses/25954970586 http://blog.crackpassword.com/2010/09/smartphone-forensics-cracking-blackberry-backup-passwords/ |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-3741 http://blog.crackpassword.com/2010/09/smartphone-forensics-cracking-blackberry-backup-passwords/ http://it.slashdot.org/story/10/10/01/166226/ http://twitter.com/elcomsoft/statuses/25954970586 http://www.infoworld.com/t/mobile-device-management/you-can-no-longer-rely-encryption-protect-blackberry-436 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7360 |
| Copyright | Copyright (c) 2010 Greenbone Networks GmbH |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|