The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the submission of username/password details during the authentication process, as demonstrated by Mobile@Work (aka com.mobileiron). The key is in the com/mobileiron/common/utils/C4928m.java file. NOTE: It has been asserted that there is no causality or connection between credential encryption and the MiTM attack
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:55:10.836Z
Reserved: 2020-12-11T00:00:00
Link: CVE-2020-35138
No data.
Status : Modified
Published: 2021-03-29T20:15:13.077
Modified: 2024-11-21T05:26:50.673
Link: CVE-2020-35138
No data.
OpenCVE Enrichment
No data.
Weaknesses