Home
MEDIUM: 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NDefault status
unaffected
5.0.420
affected
Description
An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll an attacker-controlled device to the victim’s account and telephone number.
Problem types
CWE-307 Improper Restriction of Excessive Authentication Attempts
CWE-334 Small Space of Random Values
Product status
5.0.420
References
support.blackberry.com/pkb/s/article/140220