CVE-2014-1409
9.1
CRITICAL · CVSS 3.1 · EPSS 4% (pctl 90)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 4.05% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-91 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-01-08 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| mobileiron | sentry |
| mobileiron | virtual smartphone platform |
References
- http://seclists.org/fulldisclosure/2014/Apr/21
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92351
- https://packetstormsecurity.com/files/cve/CVE-2014-1409
- http://seclists.org/fulldisclosure/2014/Apr/21
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92351
- https://packetstormsecurity.com/files/cve/CVE-2014-1409
→ the Explorer · watch your stack · NVD