SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2020-35137

HIGH · CVSS 7.5 EPSS 1.56% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-03-29 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It affects Android, Java. Public exploit code or proof-of-concept references have been detected in its references.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2020-35137
Severity
HIGH
CVSS
7.5
EPSS
1.56%
Android Java

Original NVD Description

The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded API key, used to communicate with the MobileIron SaaS discovery API, as demonstrated by Mobile@Work (aka com.mobileiron). The key is in com/mobileiron/registration/RegisterActivity.java and can be used for api/v1/gateway/customers/servers requests. NOTE: Vendor states that this is an opt-in feature to the product - it is not enabled by default and customers cannot enable it without an explicit email to support. At this time, they do not plan change to make any changes to this feature.

Related CVEs

Other vulnerabilities affecting the same vendor(s)