CVE-2014-1409

CRITICAL

Mobileiron Virtual Smartphone Platform < 5.9.1 - Authentication Bypass

Title source: rule
STIX 2.1

Description

MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords

Scores

CVSS v3 9.1
EPSS 0.0036
EPSS Percentile 58.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-91
Status published
Products (2)
mobileiron/sentry < 5.0
mobileiron/virtual_smartphone_platform < 5.9.1
Published Jan 08, 2020
Tracked Since Feb 18, 2026