MobileIron develops a mobile device management and security platform spanning endpoint control, email integration, and enterprise connectivity products such as Sentry, Mobile@Work, Core, and Enterprise Connector. The vendor's vulnerability profile skews strongly toward critical-severity outcomes and carries an elevated tendency toward both confirmed in-the-wild exploitation and public exploit availability, reflecting the high-value, internet-facing nature of its solutions and the appeal of such platforms for lateral-movement and credential-harvesting attacks. The recurring weakness classes—hard-coded credentials, inadequate encryption strength, and XML injection vulnerabilities—cluster around authentication and data-protection mechanisms that are central to the platform's security function. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mobileiron over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15505CRITICAL A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sen | Jul 7, 2020 | 9.8 | 98 | YES | YES |
CVE-2020-15506CRITICAL An authentication bypass vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that al | Jul 7, 2020 | 9.8 | 32 | NO | NO |
CVE-2020-35138CRITICAL The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the submission of username/password details during the authenticati | Mar 29, 2021 | 9.8 | 28 | NO | NO |
CVE-2013-7287CRITICAL MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme. | Feb 13, 2020 | 9.8 | 28 | NO | NO |
CVE-2020-15507HIGH An arbitrary file reading vulnerability in MobileIron Core versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote | Jul 7, 2020 | 7.5 | 26 | NO | NO |
CVE-2014-1409CRITICAL MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords | Jan 8, 2020 | 9.1 | 24 | NO | NO |
CVE-2020-35137HIGH The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded API key, used to communicate with the MobileIron SaaS discovery API, as demonstrated by Mobile@Work | Mar 29, 2021 | 7.5 | 22 | NO | NO |
CVE-2021-3391MEDIUM MobileIron Mobile@Work through 2021-03-22 allows attackers to distinguish among valid, disabled, and nonexistent user accounts by observing the number of failed login attempts need | Mar 29, 2021 | 5.3 | 19 | NO | NO |
CVE-2014-5903MEDIUM The Mobile@Work (aka com.mobileiron) application 6.0.0.1.12R for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof serv | Sep 15, 2014 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mobileiron.
Media articles that mention a CVE ID that affects a product developed by Mobileiron — matched by CVE ID, not by vendor name.