Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mobileiron

First CVE: Sep 15, 2014Active for: 12 yearsTotal CVEs: 9

MobileIron develops a mobile device management and security platform spanning endpoint control, email integration, and enterprise connectivity products such as Sentry, Mobile@Work, Core, and Enterprise Connector. The vendor's vulnerability profile skews strongly toward critical-severity outcomes and carries an elevated tendency toward both confirmed in-the-wild exploitation and public exploit availability, reflecting the high-value, internet-facing nature of its solutions and the appeal of such platforms for lateral-movement and credential-harvesting attacks. The recurring weakness classes—hard-coded credentials, inadequate encryption strength, and XML injection vulnerabilities—cluster around authentication and data-protection mechanisms that are central to the platform's security function. Current severity, exploitation activity, and CVE counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
11.1%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Mobileiron over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 15, 2014
11 years ago
Most Recent CVE
Mar 29, 2021
1,945 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-15505CRITICAL
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sen
Jul 7, 20209.898YESYES
CVE-2020-15506CRITICAL
An authentication bypass vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that al
Jul 7, 20209.832NONO
CVE-2020-35138CRITICAL
The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the submission of username/password details during the authenticati
Mar 29, 20219.828NONO
CVE-2013-7287CRITICAL
MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.
Feb 13, 20209.828NONO
CVE-2020-15507HIGH
An arbitrary file reading vulnerability in MobileIron Core versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote
Jul 7, 20207.526NONO
CVE-2014-1409CRITICAL
MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords
Jan 8, 20209.124NONO
CVE-2020-35137HIGH
The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded API key, used to communicate with the MobileIron SaaS discovery API, as demonstrated by Mobile@Work
Mar 29, 20217.522NONO
CVE-2021-3391MEDIUM
MobileIron Mobile@Work through 2021-03-22 allows attackers to distinguish among valid, disabled, and nonexistent user accounts by observing the number of failed login attempts need
Mar 29, 20215.319NONO
CVE-2014-5903MEDIUM
The Mobile@Work (aka com.mobileiron) application 6.0.0.1.12R for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof serv
Sep 15, 20145.419NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
22%
22%
56%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (88.9%)
Unknown1 (11.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High0 (0.0%)
Unknown1 (11.1%)
User Interaction
None8 (88.9%)
Unknown1 (11.1%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (88.9%)
Unknown1 (11.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
1 CVE
11.1% of CVEs· 100th percentile
Metasploit
1 CVE
11.1% of CVEs· 98th percentile
Nuclei
1 CVE
11.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mobileiron.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mobileiron — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mobileiron's Products

View all 2 CNAs →

Top CWEs