VendorsNorthern.techmenderany version
Vulnerabilities

Northern.tech Mender any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2022-29555
The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking.
Published 2022-04-28 · Modified
8.8EPSS 0.005
CVE-2021-35342
The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the system with their JWT token after logout, because of missing invalidation (if the JWT verification cache is enabled).
Published 2021-08-27 · Modified
7.5EPSS 0.011
CVE-2024-46948
Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.
Published 2024-11-08 · Modified
5.3EPSS 0.003