First published: Wed Jan 08 2020(Updated: )
MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mobileiron Virtual Smartphone Platform | <5.9.1 | |
Mobileiron Sentry | <5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1409 is a vulnerability found in MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 that allows for authentication bypass.
CVE-2014-1409 has a severity rating of 9.1 out of 10, classified as critical.
The affected software for CVE-2014-1409 includes MobileIron Virtual Smartphone Platform (VSP) versions prior to 5.9.1 and MobileIron Sentry versions prior to 5.0.
To fix CVE-2014-1409, users should update their MobileIron VSP to version 5.9.1 or later, and update their MobileIron Sentry to version 5.0 or later.
You can find more information about CVE-2014-1409 on the following references: - [http://seclists.org/fulldisclosure/2014/Apr/21](http://seclists.org/fulldisclosure/2014/Apr/21) - [https://exchange.xforce.ibmcloud.com/vulnerabilities/92351](https://exchange.xforce.ibmcloud.com/vulnerabilities/92351) - [https://packetstormsecurity.com/files/cve/CVE-2014-1409](https://packetstormsecurity.com/files/cve/CVE-2014-1409)