SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-3246

Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite!

HIGH 9.3EPSS 6.88%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (6.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite! 1.0 SP1 (1.0.1) before bundle 36 and BlackBerry Enterprise Server 4.1 SP3 (4.1.3) through 4.1 SP5 (4.1.5) allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file attachment.

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
6.88% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-94
Affected
blackberry/enterprise server · blackberry/unite · rim/blackberry enterprise server · rim/blackberry enterprise server for domino · rim/blackberry enterprise server for exchange · rim/blackberry enterprise server for novell groupwise · rim/blackberry unite
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.