Описание
MobileIron Mobile@Work through 2021-03-22 allows attackers to distinguish among valid, disabled, and nonexistent user accounts by observing the number of failed login attempts needed to produce a Lockout error message
Ссылки
- Third Party Advisory
- Not Applicable
- Technical DescriptionThird Party Advisory
- Third Party Advisory
- Not Applicable
- Technical DescriptionThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 11.0.0.0.115r (включая)Версия до 12.11.1 (включая)
Одно из
cpe:2.3:a:mobileiron:mobile\@work:*:*:*:*:*:android:*:*
cpe:2.3:a:mobileiron:mobile\@work:*:*:*:*:*:iphone_os:*:*
EPSS
Процентиль: 58%
0.00362
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
github
больше 3 лет назад
MobileIron Mobile@Work through 2021-03-22 allows attackers to distinguish among valid, disabled, and nonexistent user accounts by observing the number of failed login attempts needed to produce a Lockout error message
EPSS
Процентиль: 58%
0.00362
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
NVD-CWE-noinfo