Known Vulnerabilities for products from Mobileiron

Listed below are 9 of the newest known vulnerabilities associated with the vendor "Mobileiron".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2021-3391 json MobileIron Mobile@Work through 2021-03-22 allows attackers to distinguish among valid, disabled, and nonexistent user account... 5.3 - MEDIUM 2021-03-29 2021-04-06
CVE-2020-35138 json ** DISPUTED ** The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encry... 9.8 - CRITICAL 2021-03-29 2023-11-07
CVE-2020-35137 json ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: the reported issue is not a vulnerability or exposur... 7.5 - HIGH 2021-03-29 2023-11-07
CVE-2020-15507 json An arbitrary file reading vulnerability in MobileIron Core versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.... 7.5 - HIGH 2020-07-07 2021-07-21
CVE-2020-15506 json An authentication bypass vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4... 9.8 - CRITICAL 2020-07-07 2021-07-21
CVE-2020-15505 json A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.... 9.8 - CRITICAL 2020-07-07 2023-01-27
CVE-2014-5903 json The Mobile@Work (aka com.mobileiron) application 6.0.0.1.12R for Android does not verify X.509 certificates from SSL servers,... Not Provided 2014-09-15 2026-05-06
CVE-2014-1409 json MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an... 9.1 - CRITICAL 2020-01-08 2020-01-10
CVE-2013-7287 json MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme. 9.8 - CRITICAL 2020-02-13 2020-02-21

Known software with vulnerabilities from Mobileiron

Type Vendor Product Version
ApplicationMobileironCloud-
ApplicationMobileironCore-
ApplicationMobileironEnterprise Connector-
ApplicationMobileironMobileiron Core10.0
ApplicationMobileironMonitor And Reporting Database-
ApplicationMobileironReporting Database-
ApplicationMobileironSentry-

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report