First published: Mon Mar 29 2021(Updated: )
MobileIron Mobile@Work through 2021-03-22 allows attackers to distinguish among valid, disabled, and nonexistent user accounts by observing the number of failed login attempts needed to produce a Lockout error message
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mobileiron Mobile\@work | <=11.0.0.0.115r | |
<=12.11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this MobileIron Mobile@Work vulnerability is CVE-2021-3391.
The title of the MobileIron Mobile@Work vulnerability is 'MobileIron Mobile@Work through 2021-03-22 allows attackers to distinguish among valid disabled and nonexistent user accounts by observing failed login attempts.'
The severity of CVE-2021-3391 MobileIron Mobile@Work vulnerability is medium with a severity value of 5.3.
CVE-2021-3391 MobileIron Mobile@Work vulnerability allows attackers to distinguish among valid, disabled, and nonexistent user accounts by observing the number of failed login attempts needed to produce a Lockout error message.
To fix CVE-2021-3391 MobileIron Mobile@Work vulnerability, it is recommended to apply the latest security updates available from MobileIron.