Skip to main content

Vendor/product archive

northern.tech / mender CVEs

Beta · best-effort

5 CVEs tagged to northern.tech / mender1 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2022-32290

Published Jul 6, 2022

The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivileged TCP port and exposes an HTTP proxy to facilitate API…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29556

Published Apr 28, 2022

The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can exec…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-29555

Published Apr 28, 2022

The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1