Vulnerabilities > CVE-2017-3891 - Incorrect Authorization vulnerability in Blackberry QNX Software Development Platform 6.6.0

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
high complexity
blackberry
CWE-863

Summary

In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with QNet enabled on networks comprising two or more QNet nodes could allow an attacker to access local and remote files or take ownership of files on other QNX nodes regardless of permissions by executing commands targeting arbitrary nodes from a secondary QNX 6.6.0 QNet node.

Vulnerable Configurations

Part Description Count
Application
Blackberry
1

Common Weakness Enumeration (CWE)