CVE-2014-1409: Critical severity mobileiron virtual smartphone platform vulnerability
MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords
Affected Software
Event History
Frequently Asked Questions
What is CVE-2014-1409?
CVE-2014-1409 is a vulnerability found in MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 that allows for authentication bypass.
How severe is CVE-2014-1409?
CVE-2014-1409 has a severity rating of 9.1 out of 10, classified as critical.
What is the affected software for CVE-2014-1409?
The affected software for CVE-2014-1409 includes MobileIron Virtual Smartphone Platform (VSP) versions prior to 5.9.1 and MobileIron Sentry versions prior to 5.0.
How can I fix CVE-2014-1409?
To fix CVE-2014-1409, users should update their MobileIron VSP to version 5.9.1 or later, and update their MobileIron Sentry to version 5.0 or later.
Where can I find more information about CVE-2014-1409?
You can find more information about CVE-2014-1409 on the following references: - [http://seclists.org/fulldisclosure/2014/Apr/21](http://seclists.org/fulldisclosure/2014/Apr/21) - [https://exchange.xforce.ibmcloud.com/vulnerabilities/92351](https://exchange.xforce.ibmcloud.com/vulnerabilities/92351) - [https://packetstormsecurity.com/files/cve/CVE-2014-1409](https://packetstormsecurity.com/files/cve/CVE-2014-1409)