CVE-2016-3127
Estado: ModificadaAlta (7.5)—
An information disclosure vulnerability in the logging implementation of BlackBerry Good Control Server versions earlier than 2.3.53.62 allows remote attackers to gain and use logged encryption keys to access certain resources within a customer's Good deployment by gaining access to certain diagnostic log files through either a valid logon or an unrelated compromise of the server.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.38%
- Percentil entre todas las CVEs puntuadas: 71
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-3127",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "secure@blackberry.com",
"affectedData": [
{
"vendor": "n/a",
"product": "BlackBerry Good Control Server versions earlier than 2.3.53.62",
"versions": [
{
"status": "affected",
"version": "BlackBerry Good Control Server versions earlier than 2.3.53.62"
}
]
}
]
}
],
"published": "2017-03-03T18:59:00.193",
"references": [
{
"url": "http://support.blackberry.com/kb/articleDetail?articleNumber=000038301",
"tags": [
"Vendor Advisory"
],
"source": "secure@blackberry.com"
},
{
"url": "http://www.securityfocus.com/bid/96629",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secure@blackberry.com"
},
{
"url": "http://support.blackberry.com/kb/articleDetail?articleNumber=000038301",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/96629",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An information disclosure vulnerability in the logging implementation of BlackBerry Good Control Server versions earlier than 2.3.53.62 allows remote attackers to gain and use logged encryption keys to access certain resources within a customer's Good deployment by gaining access to certain diagnostic log files through either a valid logon or an unrelated compromise of the server."
},
{
"lang": "es",
"value": "Una vulnerabilidad de divulgación de información en la implementación de inicio de sesión de BlackBerry Good Control Server en versiones anteriores a 2.3.53.62 permite a atacantes remotos obtener y utilizar claves de cifrado registradas para acceder a ciertos recursos dentro de la implementación Good de un cliente obteniendo acceso a ciertos archivos de registro de diagnóstico a través de un inicio de sesión válido o un comprometimiento no relacionado del servidor."
}
],
"lastModified": "2026-06-17T00:45:02.950",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:blackberry:good_control_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7FCB51F8-A854-41D6-8F6F-AD197C8A3A6D",
"versionEndIncluding": "2.2.511.26"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secure@blackberry.com"
}