CVE-2013-3694

BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not require authentication for remote file-access folders, which allows remote attackers to read or create arbitrary files via IPv6 WebDAV requests, as demonstrated by a CSRF attack involving DNS rebinding.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
blackberryblackberry_link
𝑥
≤ 1.1.1.26
blackberryblackberry_link
1.0.1.12
blackberryblackberry_link
𝑥
≤ 1.2.0.28
blackberryblackberry_link
1.0.1.12
blackberryblackberry_link
1.1.1.26
blackberryblackberry_link
1.1.1.41
blackberryblackberry_link
1.2.0.12
𝑥
= Vulnerable software versions