CVE-2017-9371
Estado: ModificadaBaja (2.6)—
In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default configuration of the QNX SDP could allow an attacker being able to reduce the entropy of the PRNG, making other blended attacks more practical by gaining control over environmental factors that influence seed generation.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
- Puntuación base: 2.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.81%
- Percentil entre todas las CVEs puntuadas: 55
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-332
- CWE-332
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-9371",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.2
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "secure@blackberry.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 2.6,
"attackVector": "PHYSICAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "secure@blackberry.com",
"affectedData": [
{
"vendor": "BlackBerry",
"product": "QNX Software Development Platform (QNX SDP)",
"versions": [
{
"status": "affected",
"version": "6.6.0"
},
{
"status": "affected",
"version": "6.5.0 SP1 and earlier"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2017-11-14T21:29:01.167",
"references": [
{
"url": "http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000046674",
"tags": [
"Vendor Advisory"
],
"source": "secure@blackberry.com"
},
{
"url": "http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000046674",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "secure@blackberry.com",
"description": [
{
"lang": "en",
"value": "CWE-332"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-332"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default configuration of the QNX SDP could allow an attacker being able to reduce the entropy of the PRNG, making other blended attacks more practical by gaining control over environmental factors that influence seed generation."
},
{
"lang": "es",
"value": "En BlackBerry QNX Software Development Platform (SDP) 6.6.0 y 6.5.0 SP1 y anteriores, una vulnerabilidad de pérdida de integridad en la configuración por defecto de la plataforma QNX SDP podría permitir que un atacante sea capaz de reducir la entropía del PRNG, haciendo que otros ataques combinados sean más prácticos mediante la obtención del control sobre factores del entorno que influyen en la generación de semillas."
}
],
"lastModified": "2026-06-17T01:27:58.860",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:blackberry:qnx_software_development_platform:6.5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1766E1E7-19FE-45A5-8191-BA0CF84BB768"
},
{
"criteria": "cpe:2.3:a:blackberry:qnx_software_development_platform:6.5.0:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "11F2C680-2F44-4CBC-BC7E-B608726302D2"
},
{
"criteria": "cpe:2.3:a:blackberry:qnx_software_development_platform:6.6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF1D7FB0-C40B-4DD6-B3C5-D90FBCCBAF23"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secure@blackberry.com"
}