CRITICAL🇵🇱 Wersja polska

CVE-2014-1409

CVSS 9.1v3.1pub. 2020-01-08upd. 2024-11-21

MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Mobileiron Sentry

    APP
    Mobileiron
    < 5.0
  • Mobileiron Virtual Smartphone Platform

    APP
    Mobileiron
    < 5.9.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2020-15505CRITICAL9.8⚠ KEVPL ✓same product

Zdalne wykonanie kodu (RCE) w MobileIron Core, Sentry i RDB

CVE-2020-15506CRITICAL9.8PL ✓same product

Authentication bypass w MobileIron Core & Connector — pominięcie uwierzytelnienia

CVE-2013-7287CRITICAL9.8PL ✓same product

Słaby schemat szyfrowania w MobileIron VSP i Sentry

CVE-2020-15507HIGH7.5same product

An arbitrary file reading vulnerability in MobileIron Core versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, ...

CVE-2020-35138CRITICAL9.8PL ✓same vendor

MobileIron Mobile@Work — zakodowany klucz szyfrowania poświadczeń