In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default configuration of the QNX SDP could allow an attacker being able to reduce the entropy of the PRNG, making other blended attacks more practical by gaining control over environmental factors that influence seed generation.
Advisories
Source ID Title
EUVD EUVD EUVD-2017-18306 In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default configuration of the QNX SDP could allow an attacker being able to reduce the entropy of the PRNG, making other blended attacks more practical by gaining control over environmental factors that influence seed generation.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 22 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: blackberry

Published:

Updated: 2025-08-22T15:05:29.013Z

Reserved: 2017-06-02T00:00:00

Link: CVE-2017-9371

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-11-14T21:29:01.167

Modified: 2025-08-22T15:15:30.517

Link: CVE-2017-9371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.