Vulnerability Description
The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the submission of username/password details during the authentication process, as demonstrated by Mobile@Work (aka com.mobileiron). The key is in the com/mobileiron/common/utils/C4928m.java file. NOTE: It has been asserted that there is no causality or connection between credential encryption and the MiTM attack
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mobileiron | Mobile\@Work | <= 2021-03-22 |
Related Weaknesses (CWE)
References
- https://github.com/optiv/rustyIronExploitThird Party Advisory
- https://play.google.com/store/apps/details?id=com.mobileiron&hl=en_US&gl=USProductThird Party Advisory
- https://www.ivanti.com/blog/a-warranted-response-to-inaccurate-optiv-researchThird Party Advisory
- https://www.optiv.com/explore-optiv-insights/source-zero/mobileiron-mdm-containsExploitThird Party Advisory
- https://www.optiv.com/insights/source-zero/blog/mobileiron-mdm-contains-static-kExploitThird Party Advisory
- https://github.com/optiv/rustyIronExploitThird Party Advisory
- https://play.google.com/store/apps/details?id=com.mobileiron&hl=en_US&gl=USProductThird Party Advisory
- https://www.ivanti.com/blog/a-warranted-response-to-inaccurate-optiv-researchThird Party Advisory
- https://www.optiv.com/explore-optiv-insights/source-zero/mobileiron-mdm-containsExploitThird Party Advisory
- https://www.optiv.com/insights/source-zero/blog/mobileiron-mdm-contains-static-kExploitThird Party Advisory
FAQ
What is CVE-2020-35138?
CVE-2020-35138 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the submission of username/password details during the authentication process, as demon...
How severe is CVE-2020-35138?
CVE-2020-35138 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-35138?
Check the references section above for vendor advisories and patch information. Affected products include: Mobileiron Mobile\@Work.