Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mobile\@work CRITICAL 9.8
CVE-2020-35138

The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the submission of username/password …

Fix: after 2021-03-22
Fix from $2,300 2021-03-29
Mobile\@work HIGH 7.5
CVE-2020-35137

The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded API key, used to communicate with the MobileIron SaaS discovery API,…

Fix: after 2021-03-22
Fix from $1,950 2021-03-29
Mobile\@work MEDIUM 5.3
CVE-2021-3391

MobileIron Mobile@Work through 2021-03-22 allows attackers to distinguish among valid, disabled, and nonexistent user accounts by observing the numbe…

Fix: after 12.11.1
Fix from $1,600 2021-03-29
Core CRITICAL 9.8
CVE-2020-15505 KEVEPSS 100%

A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0,…

Fix: 2.0.0.2 / 9.7.3+
Fix from $2,300 2020-07-07
Cloud CRITICAL 9.8
CVE-2020-15506

An authentication bypass vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0…

Fix: after 10.6
Fix from $2,300 2020-07-07
Cloud HIGH 7.5
CVE-2020-15507

An arbitrary file reading vulnerability in MobileIron Core versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 …

Fix: after 10.6
Fix from $1,950 2020-07-07
Sentry CRITICAL 9.8
CVE-2013-7287

MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.

Fix: 5.0 / 5.9.1+
Fix from $2,300 2020-02-13
Virtual Smartphone Platform CRITICAL 9.1
CVE-2014-1409

MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscate…

Fix: 5.0 / 5.9.1+
Fix from $2,300 2020-01-08
Mobile\@work MEDIUM 5.4
CVE-2014-5903

The Mobile@Work (aka com.mobileiron) application 6.0.0.1.12R for Android does not verify X.509 certificates from SSL servers, which allows man-in-the…

Mitigation only
Fix from $1,600 2014-09-15