Vulnerability in the security of BlackBerry device backups using the BlackBerry Desktop Software
20 Apr. 2010
Summary
This advisory describes an issue related to how the BlackBerry Desktop Software version 1.0 for Mac and the BlackBerry Desktop Software version 4.7 through 6.0 for PC encrypts BlackBerry device backup files. The issue may allow a malicious user to decrypt the backup file by means of a brute force attack (repetitive password guessing attempts).
Immune Systems:
*BlackBerry Device Software
*BlackBerry Enterprise Software
*BlackBerry Internet Service
*BlackBerry Desktop Software versions earlier than 4.7 (PC OS)
Successful exploitation of the issue using the affected versions of the BlackBerry Desktop Software requires the following steps:
1.The BlackBerry Desktop Software user uses a weak password that is susceptible to brute force attacks to encrypt the backup file. Note that the encryption key generation process adds a random value to the password the user chooses to improve the strength of the password before generating the encryption key.
2.The malicious user must be able to gain access to the backup file.
3.The malicious user would need to rely on repeated attempts to determine the password to decrypt the backup file.
Vendor Status:
Blackberry had issued an update for this vulnerability