CVE-2024-46948
- EPSS 0.38%
- Veröffentlicht 08.11.2024 16:15:24
- Zuletzt bearbeitet 10.02.2025 23:15:14
Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.
CVE-2024-46947
- EPSS 0.29%
- Veröffentlicht 08.11.2024 16:15:23
- Zuletzt bearbeitet 08.11.2024 19:35:17
Northern.tech Mender before 3.6.6 and 3.7.x before 3.7.7 allows SSRF.
CVE-2022-41324
- EPSS 0.13%
- Veröffentlicht 20.06.2024 17:15:50
- Zuletzt bearbeitet 14.03.2025 01:15:37
Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information.
CVE-2022-45929
- EPSS 0.14%
- Veröffentlicht 20.06.2024 17:15:50
- Zuletzt bearbeitet 21.11.2024 07:29:58
Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could allow privilege escalation from a low-privileged read-only user to a high-privileged use...
CVE-2024-37019
- EPSS 1.31%
- Veröffentlicht 03.06.2024 18:15:08
- Zuletzt bearbeitet 21.11.2024 09:23:03
Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.
CVE-2022-32290
- EPSS 0.07%
- Veröffentlicht 06.07.2022 12:15:08
- Zuletzt bearbeitet 21.11.2024 07:06:06
The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivileged TCP port and exposes an HTTP proxy to facilitate API calls from additional client components running on the device. However,...
CVE-2022-29555
- EPSS 0.15%
- Veröffentlicht 28.04.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:18
The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking.
CVE-2022-29556
- EPSS 0.43%
- Veröffentlicht 28.04.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:18
The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal API endpoints.