Northern.tech
Northern.tech Cfengine: vulnerabilidades y CVE
Northern.tech Cfengine tiene 10 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-24712 | Alta (7.3) | 0.92% | — | 14 may 2026 | Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection. |
| CVE-2026-24711 | Media (5.3) | 0.21% | — | 14 may 2026 | Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control. |
| CVE-2026-24710 | Media (6.1) | 0.17% | — | 14 may 2026 | Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS. |
| CVE-2023-45684 | Alta (7.5) | 0.65% | — | 14 nov 2023 | Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub. |
| CVE-2023-26560 | Media (6.5) | 0.55% | — | 26 abr 2023 | Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials. |
| CVE-2021-44216 | Media (5.5) | 0.36% | — | 10 mar 2022 | Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files. |
| CVE-2021-44215 | Media (5.5) | 0.35% | — | 10 mar 2022 | Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact. |
| CVE-2021-38379 | Media (5.5) | 0.21% | — | 27 oct 2021 | The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure. |
| CVE-2021-36756 | Media (6.5) | 0.42% | — | 27 oct 2021 | CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation. |
| CVE-2019-19394 | Media (6.1) | 0.64% | — | 16 abr 2020 | Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.