PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-3128 Blackberry CVE debrief

CVE-2016-3128 is a spoofing vulnerability in the core of BlackBerry Enterprise Server (BES) 12 through 12.5.2. According to the CVE record, a remote attacker could use information tied to a legitimately enrolled device to enroll an illegitimate device, access device parameters for the BES, or send false information to the BES. NVD lists the issue as CVSS 3.0 8.2 (HIGH) with network attack vector, no privileges, and no user interaction.

Vendor
Blackberry
Product
Enterprise Service
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-13
Original CVE updated
2026-05-13
Advisory published
2017-01-13
Advisory updated
2026-05-13

Who should care

Organizations operating BlackBerry Enterprise Server 12.x deployments, especially environments still running BES 12.0.0 through 12.5.2, should treat this as relevant because it affects device enrollment and trust relationships in the management plane.

Technical summary

NVD maps the vulnerability to BlackBerry Enterprise Server versions 12.0.0, 12.0.1, 12.1.0, 12.2.0, 12.2.1, 12.3.0, 12.3.1, 12.4.0, 12.4.1, 12.5.0a, 12.5.1, and 12.5.2. The weakness is classified as CWE-254. The CVSS vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N, indicating a network-reachable issue with potentially high integrity impact and limited confidentiality impact.

Defensive priority

High for any active BES 12.x deployment that still manages devices or enrollment workflows. The issue directly affects trust in device identity and administrative data flow, which can have downstream operational and security consequences.

Recommended defensive actions

  • Inventory all BlackBerry Enterprise Server 12.x instances and confirm whether any affected versions from 12.0.0 through 12.5.2 are in use.
  • Review the BlackBerry vendor advisory referenced by NVD for mitigation or remediation guidance.
  • Restrict exposure of BES management and enrollment interfaces to trusted administrative networks where possible.
  • Audit enrolled devices and enrollment records for anomalies that could indicate spoofed or illegitimate device enrollment.
  • If a vulnerable version is present, prioritize vendor-recommended remediation and verify after changes that enrollment and device-parameter workflows behave as expected.

Evidence notes

The debrief is based only on the supplied CVE record, the NVD metadata, and the referenced BlackBerry advisory link listed in the source corpus. The CVE description explicitly identifies a spoofing issue in the core of BES 12 through 12.5.2 and the risk of illegitimate device enrollment, device-parameter access, and false information submission. NVD provides the affected version list, CVSS vector, and CWE-254 classification.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-3128 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-3128

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-3128 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-3128

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.