Site icon IT World Canada

BlackBerry products vulnerable to FREAK attack

Many versions of the BlackBerry operating systems and BlackBerry Enterprise Server are vulnerable to the FREAK SSL attack, according to a warning issued by the company.

The OpenSSL FREAK (Factoring Attack on RSA-Export Keys) vulnerability or CVE-2015-0204, which was reported March 3, is believed to have for years made iPhones, Mac OS X machines and Google Android devices vulnerable to hacking.

In a security advisory, BlackBerry confirmed that its products (software and smart phones) are also affected by the flaw. The company said it is investigating the vulnerability and is doing its best to mitigate customer risk. BlackBerry is not aware of any customers that may have been subjected to an attack that exploited the vulnerability.

BlackBerry said there are no workarounds to the vulnerability.

FREAK is a vulnerability in the OpenSSL implementation included with affected BlackBerry products. The popular OpenSSL cryptographic software library is open-source software used to secure client/server transactions.

The weakness could allow an attacker who is able to intercept and modify encrypted SSL traffic to force a weaker cipher suite. This weaker cipher suite could be broken by a brute force attack within a finite time. In order to exploit this vulnerability, an attacker must first complete a successful man-in-the-middle attack.

The affected BlackBerry software are:

Non-affected software are:

Exit mobile version