CVE-2017-3891
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with QNet enabled on networks comprising two or more QNet nodes could allow an attacker to access local and remote files or take ownership of files on other QNX nodes regardless of permissions by executing commands targeting arbitrary nodes from a secondary QNX 6.6.0 QNet node.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.6
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.30%
- CWE
- CWE-923
- Published
- 2017-11-14
- Last modified
- 2026-03-14
Affected products
- BlackBerry QNX Software Development Platform (QNX SDP)
Weakness type
Related vulnerabilities
- CVE-2019-17440 — PAN-OS on PA-7000 Series: Improper restriction of communication to Log Forwarding Card (LFC) allows root access
- CVE-2026-34205 — Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mode
- CVE-2023-28078 — Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A
- CVE-2025-61939 — Columbia Weather Systems MicroServer Improper Restriction of Communication Channel to Intended Endpoints
- CVE-2025-20261 — Cisco Integrated Management Controller Privilege Escalation Vulnerability
- CVE-2021-38487 — Potential Network Amplification and Information Exposure in RTI Connext Professional and Connext Micro
- CVE-2025-58742 — Insufficient Configuration Protections Enable Database Credential Interception in Milner ImageDirector Capture
- CVE-2024-26131 — Element Android Intent Redirection