CVE-2020-15506 is a critical authentication bypass vulnerability affecting various versions of MobileIron Core and Connector, allowing remote attackers to bypass authentication mechanisms. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network without requiring user interaction or privileges, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been confirmed, its high severity and media coverage indicate significant risk. The vulnerability has garnered some community discussion and media attention, highlighting its potential impact despite the lack of confirmed active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.6CPE matchmatch criteria | cpe:2.3:a:mobileiron:cloud:*:*:*:*:*:*:*:* | ||
<= 10.6CPE matchmatch criteria | cpe:2.3:a:mobileiron:core:*:*:*:*:*:*:*:* | ||
<= 10.6CPE matchmatch criteria | cpe:2.3:a:mobileiron:enterprise_connector:*:*:*:*:*:*:*:* | ||
<= 10.6CPE matchmatch criteria | cpe:2.3:a:mobileiron:reporting_database:*:*:*:*:*:*:*:* | ||
<= 10.6CPE matchmatch criteria | cpe:2.3:a:mobileiron:sentry:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.