CVE-2013-7286: Weak Encryption
Published Feb 12, 2020
·Updated
MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm
Affected Software
2 affected components
Att Mobileiron Sentry<5.0
Att Mobileiron Virtual Smartphone Platform<5.9.1
Event History
Feb 12, 2020
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2013-7286.
2
What is the severity level of CVE-2013-7286?
The severity level of CVE-2013-7286 is high with a CVSS score of 7.5.
3
What is affected by CVE-2013-7286?
MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 are affected by CVE-2013-7286.
4
What is the impact of CVE-2013-7286?
This vulnerability allows attackers to bypass authentication and gain unauthorized access to MobileIron VSP and Sentry systems.
5
How can I fix CVE-2013-7286?
To fix CVE-2013-7286, update MobileIron VSP to version 5.9.1 or later and update Sentry to version 5.0 or later.