MobileIron Mobile@Work through 2021-03-22 allows attackers to distinguish among valid, disabled, and nonexistent user accounts by observing the number of failed login attempts needed to produce a Lockout error message
Conclusion & alert: CVE-2021-3391 is rated Moderate Risk (43.9/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.15%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.36% | 1.15% | +0.79% |
| 2 | 2025-03-17 | 0.07% | 0.36% | +0.29% |
| 3 | 2023-03-07 | — | 0.07% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| mobileiron | mobile\@work | <= 11.0.0.0.115r | cpe:2.3:a:mobileiron:mobile\@work:*:*:*:*:*:android:*:* |
| mobileiron | mobile\@work | <= 12.11.1 | cpe:2.3:a:mobileiron:mobile\@work:*:*:*:*:*:iphone_os:*:* |
| URL | Tags |
|---|---|
| https://github.com/optiv/rustyIron | Third Party Advisory |
| https://www.mobileiron.com/en/blog/mobileiron-security-updates-available | Not Applicable |
| https://www.optiv.com/explore-optiv-insights/source-zero/mobileiron-mdm-contains-static-key-allowing-account-enumeration | Technical Description Third Party Advisory |