CVE-2014-1409

CRITICAL

MobileIron Virtual Smartphone Platform < 5.9.1 and Sentry < 5.0 - Authentication Bypass via XML Password Obfuscation

Title source: llm
STIX 2.1

Description

MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords

References (3)

Core 3
Core References
Exploit, Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/fulldisclosure/2014/Apr/21
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/92351
Third Party Advisory, VDB Entry x_refsource_misc
https://packetstormsecurity.com/files/cve/CVE-2014-1409

Scores

CVSS v3 9.1
EPSS 0.0405
EPSS Percentile 89.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-91
Status published
Products (2)
mobileiron/sentry < 5.0
mobileiron/virtual_smartphone_platform < 5.9.1
Published Jan 08, 2020
Tracked Since Feb 18, 2026