[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-3741Date: (C)2010-10-05   (M)2023-12-22


The offline backup mechanism in Research In Motion (RIM) BlackBerry Desktop Software uses single-iteration PBKDF2, which makes it easier for local users to decrypt a .ipd file via a brute-force attack.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.7
Exploit Score: 3.4
Impact Score: 6.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: NONE
Availability: NONE
  
Reference:
http://blog.crackpassword.com/2010/09/smartphone-forensics-cracking-blackberry-backup-passwords/
http://it.slashdot.org/story/10/10/01/166226/
http://twitter.com/elcomsoft/statuses/25954970586
http://www.infoworld.com/t/mobile-device-management/you-can-no-longer-rely-encryption-protect-blackberry-436
oval:org.mitre.oval:def:7360

CPE    1
cpe:/a:rim:blackberry_desktop_software
CWE    1
CWE-310
OVAL    1
oval:org.mitre.oval:def:7360

© SecPod Technologies