PT-2021-11716 · Mobileiron · Mobileiron
Published
2021-03-29
·
Updated
2024-08-04
·
CVE-2020-35138
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
MobileIron agents through 2021-03-22 for Android and iOS
Description:
The issue concerns a hardcoded encryption key used to encrypt username and password details during the authentication process. This key is located in the com/mobileiron/common/utils/C4928m.java file. It has been noted that there is no connection between credential encryption and the Man-in-the-Middle (MiTM) attack.
Recommendations:
For MobileIron agents through 2021-03-22 for Android and iOS, consider updating to a version released after 2021-03-22 to ensure the removal of the hardcoded encryption key. As a temporary workaround, restrict access to sensitive authentication processes until a patch is available. Avoid using the affected MobileIron agents for sensitive transactions until the issue is resolved.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mobileiron