ID

VAR-201704-0112


CVE

CVE-2016-2433


TITLE

BlackBerry Used on smartphone Android for Broadcom Wi-Fi Driver vulnerable to arbitrary code execution in the context of the kernel

Trust: 0.8

sources: JVNDB: JVNDB-2016-008531

DESCRIPTION

The Broadcom Wi-Fi driver for Android, as used by BlackBerry smartphones before Build AAE570, allows remote attackers to execute arbitrary code in the context of the kernel. BlackBerrysmartphones are smart phones made by the BlackBerry. Broadcom Wi-FidriverforAndroid is a Wi-Fi driver module developed by Broadcom Inc. in the Android system. There is a security vulnerability in Broadcom Wi-FidriverforAndroid used in previous versions of the BlackBerry smartphone BuildAAE570

Trust: 2.43

sources: NVD: CVE-2016-2433 // JVNDB: JVNDB-2016-008531 // CNVD: CNVD-2017-06902 // BID: 98034

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-06902

AFFECTED PRODUCTS

vendor:googlemodel:androidscope:lteversion:6.0.1

Trust: 1.0

vendor:googlemodel:androidscope: - version: -

Trust: 0.8

vendor:blackberrymodel:smartphone <build aae570scope: - version: -

Trust: 0.6

vendor:googlemodel:androidscope:eqversion:6.0.1

Trust: 0.6

vendor:blackberrymodel:smartphonescope:eqversion:0

Trust: 0.3

vendor:blackberrymodel:smartphone build aae570scope:neversion: -

Trust: 0.3

sources: CNVD: CNVD-2017-06902 // BID: 98034 // JVNDB: JVNDB-2016-008531 // CNNVD: CNNVD-201704-1144 // NVD: CVE-2016-2433

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-2433
value: HIGH

Trust: 1.0

NVD: CVE-2016-2433
value: HIGH

Trust: 0.8

CNVD: CNVD-2017-06902
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201704-1144
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2016-2433
severity: HIGH
baseScore: 8.3
vectorString: AV:A/AC:L/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-06902
severity: HIGH
baseScore: 8.3
vectorString: AV:A/AC:L/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2016-2433
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2017-06902 // JVNDB: JVNDB-2016-008531 // CNNVD: CNNVD-201704-1144 // NVD: CVE-2016-2433

PROBLEMTYPE DATA

problemtype:CWE-284

Trust: 1.8

sources: JVNDB: JVNDB-2016-008531 // NVD: CVE-2016-2433

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-201704-1144

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201704-1144

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-008531

PATCH

title:トップページurl:https://www.android.com/intl/ja_jp/

Trust: 0.8

title:BlackBerry powered by Android Security Bulletin &#8211; May 2016url:http://support.blackberry.com/kb/articleDetail?articleNumber=000038167

Trust: 0.8

title:BlackBerry smart machine BroadcomWi-FidriverforAndroid random code execution vulnerability patchurl:https://www.cnvd.org.cn/patchInfo/show/93904

Trust: 0.6

title:BlackBerry smartphone Broadcom Wi-Fi driver for Android Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=69719

Trust: 0.6

sources: CNVD: CNVD-2017-06902 // JVNDB: JVNDB-2016-008531 // CNNVD: CNNVD-201704-1144

EXTERNAL IDS

db:NVDid:CVE-2016-2433

Trust: 3.3

db:BIDid:98034

Trust: 1.9

db:JVNDBid:JVNDB-2016-008531

Trust: 0.8

db:CNVDid:CNVD-2017-06902

Trust: 0.6

db:CNNVDid:CNNVD-201704-1144

Trust: 0.6

sources: CNVD: CNVD-2017-06902 // BID: 98034 // JVNDB: JVNDB-2016-008531 // CNNVD: CNNVD-201704-1144 // NVD: CVE-2016-2433

REFERENCES

url:http://support.blackberry.com/kb/articledetail?articlenumber=000038167

Trust: 1.9

url:http://www.securityfocus.com/bid/98034

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2016-2433

Trust: 1.4

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-2433

Trust: 0.8

url:http://code.google.com/android/

Trust: 0.3

url:http://us.blackberry.com/

Trust: 0.3

sources: CNVD: CNVD-2017-06902 // BID: 98034 // JVNDB: JVNDB-2016-008531 // CNNVD: CNNVD-201704-1144 // NVD: CVE-2016-2433

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 98034

SOURCES

db:CNVDid:CNVD-2017-06902
db:BIDid:98034
db:JVNDBid:JVNDB-2016-008531
db:CNNVDid:CNNVD-201704-1144
db:NVDid:CVE-2016-2433

LAST UPDATE DATE

2025-04-20T23:22:24.482000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-06902date:2017-05-18T00:00:00
db:BIDid:98034date:2017-05-02T04:09:00
db:JVNDBid:JVNDB-2016-008531date:2017-06-02T00:00:00
db:CNNVDid:CNNVD-201704-1144date:2017-05-02T00:00:00
db:NVDid:CVE-2016-2433date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-06902date:2017-05-18T00:00:00
db:BIDid:98034date:2017-04-21T00:00:00
db:JVNDBid:JVNDB-2016-008531date:2017-06-02T00:00:00
db:CNNVDid:CNNVD-201704-1144date:2017-04-21T00:00:00
db:NVDid:CVE-2016-2433date:2017-04-21T20:59:00.603