CVE-2014-1409
CRITICALMobileiron Virtual Smartphone Platform < 5.9.1 - Authentication Bypass
Title source: ruleDescription
MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords
Scores
CVSS v3
9.1
EPSS
0.0036
EPSS Percentile
58.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Details
CWE
CWE-91
Status
published
Products (2)
mobileiron/sentry
< 5.0
mobileiron/virtual_smartphone_platform
< 5.9.1
Published
Jan 08, 2020
Tracked Since
Feb 18, 2026