Northern.tech
Northern.tech Mender: vulnerabilidades y CVE
Northern.tech Mender tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-47190 | Baja (2.7) | 0.28% | — | 8 nov 2024 | Northern.tech Hosted Mender before 2024.07.11 allows SSRF. |
| CVE-2024-46948 | Media (4.3) | 0.26% | — | 8 nov 2024 | Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control. |
| CVE-2024-46947 | Media (6.5) | 0.39% | — | 8 nov 2024 | Northern.tech Mender before 3.6.6 and 3.7.x before 3.7.7 allows SSRF. |
| CVE-2022-45929 | Alta (8.8) | 0.38% | — | 20 jun 2024 | Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could allow privilege escalation from a low-privileged… |
| CVE-2022-41324 | Media (6.5) | 0.32% | — | 20 jun 2024 | Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information. |
| CVE-2022-32290 | Media (4.3) | 0.22% | — | 6 jul 2022 | The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivileged TCP port and exposes an HTTP proxy to facilitate API calls from additional client components… |
| CVE-2022-29556 | Crítica (9.8) | 1.0% | — | 28 abr 2022 | The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal… |
| CVE-2022-29555 | Alta (8.8) | 0.48% | — | 28 abr 2022 | The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking. |