Executive brief
A vulnerability in BlackBerry Enterprise Server (BES) 12 allows unauthorized individuals to enroll illegitimate mobile devices into the corporate management system. By exploiting this flaw, an attacker could gain access to internal device parameters or feed false information to the server, potentially compromising the integrity of the mobile device management environment. This could lead to unauthorized access to corporate resources or the introduction of unmanaged devices into the secure network.
Technical details
A spoofing vulnerability exists in the Core component of BlackBerry Enterprise Server (BES) versions 12 through 12.5.2. The flaw allows a remote, unauthenticated attacker to enroll an illegitimate device into the BES environment by obtaining specific information about a device that was already legitimately enrolled. Once enrolled, the attacker can access device parameters or transmit fraudulent data to the BES. The vulnerability is classified under CWE-254 (Security Features) and has been addressed in later versions of the software.
Affected products
- BlackBerry BlackBerry Enterprise Service (BES) 12 12.0 through 12.5.2
Timeline
- 2017-01-13: disclosed
- 2017-01-13: advisory