MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMobileiron Sentry
APPMobileiron< 5.0Mobileiron Virtual Smartphone Platform
APPMobileiron< 5.9.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2020-15505CRITICAL9.8⚠ KEVPL ✓same product
Zdalne wykonanie kodu (RCE) w MobileIron Core, Sentry i RDB
CVE-2020-15506CRITICAL9.8PL ✓same product
Authentication bypass w MobileIron Core & Connector — pominięcie uwierzytelnienia
CVE-2014-1409CRITICAL9.1PL ✓same product
MobileIron VSP i Sentry — pominięcie uwierzytelnienia przez zaciemnione hasła w XML
CVE-2020-15507HIGH7.5same product
An arbitrary file reading vulnerability in MobileIron Core versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, ...
CVE-2020-35138CRITICAL9.8PL ✓same vendor
MobileIron Mobile@Work — zakodowany klucz szyfrowania poświadczeń