ZeroHour

CVE-2016-3130

CVSS 3.0
8.1 high
EPSS
2%p80
Published
()
Modified
Description

An information disclosure vulnerability in the Core and Management Console in BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to obtain local or domain credentials of an administrator or user account by sniffing traffic between the two elements during a login attempt.

Vendors
blackberry
Products
enterprise service
Weakness
CWE-200, CWE-255
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.