CVE-2021-3391: Medium severity MobileIron Mobile\@work Android vulnerability
MobileIron Mobile@Work through 2021-03-22 allows attackers to distinguish among valid, disabled, and nonexistent user accounts by observing the number of failed login attempts needed to produce a Lockout error message
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this MobileIron Mobile@Work vulnerability?
The vulnerability ID for this MobileIron Mobile@Work vulnerability is CVE-2021-3391.
What is the title of the MobileIron Mobile@Work vulnerability?
The title of the MobileIron Mobile@Work vulnerability is 'MobileIron Mobile@Work through 2021-03-22 allows attackers to distinguish among valid disabled and nonexistent user accounts by observing failed login attempts.'
What is the severity of CVE-2021-3391 MobileIron Mobile@Work vulnerability?
The severity of CVE-2021-3391 MobileIron Mobile@Work vulnerability is medium with a severity value of 5.3.
How does CVE-2021-3391 MobileIron Mobile@Work vulnerability allow attackers to distinguish among valid, disabled, and nonexistent user accounts?
CVE-2021-3391 MobileIron Mobile@Work vulnerability allows attackers to distinguish among valid, disabled, and nonexistent user accounts by observing the number of failed login attempts needed to produce a Lockout error message.
Is there any fix available for CVE-2021-3391 MobileIron Mobile@Work vulnerability?
To fix CVE-2021-3391 MobileIron Mobile@Work vulnerability, it is recommended to apply the latest security updates available from MobileIron.