VYPR
Vendor

Northern.tech

Products
11
CVEs
30
Across products
49
Status
Private

Products

11

Recent CVEs

30
View all 30 CVEs →
  • CVE-2024-37019CriJun 3, 2024
    risk 0.64cvss 9.8epss 0.01

    Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.

  • CVE-2022-29556CriApr 28, 2022
    risk 0.64cvss 9.8epss 0.01

    The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal API endpoints.

  • CVE-2025-49603CriJun 26, 2025
    risk 0.59cvss 9.1epss 0.00

    Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control.

  • CVE-2024-55959CriJan 21, 2025
    risk 0.59cvss 9.1epss 0.01

    Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.

  • CVE-2022-45929HigJun 20, 2024
    risk 0.57cvss 8.8epss 0.00

    Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could allow privilege escalation from a low-privileged read-only user to a high-privileged user.

  • CVE-2022-29555HigApr 28, 2022
    risk 0.57cvss 8.8epss 0.00

    The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking.

  • CVE-2019-9929HigJun 6, 2019
    risk 0.57cvss 8.8epss 0.02

    Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions.

  • CVE-2023-45684HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub.

  • CVE-2021-35342HigAug 27, 2021
    risk 0.49cvss 7.5epss 0.01

    The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the system with their JWT token after logout, because of missing invalidation (if the JWT verification…

  • CVE-2026-24712HigMay 14, 2026
    risk 0.48cvss 7.3epss 0.01

    Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.

  • CVE-2024-46947MedNov 8, 2024
    risk 0.42cvss 6.5epss 0.00

    Northern.tech Mender before 3.6.6 and 3.7.x before 3.7.7 allows SSRF.

  • CVE-2022-41324MedJun 20, 2024
    risk 0.42cvss 6.5epss 0.00

    Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information.

  • CVE-2023-26560MedApr 26, 2023
    risk 0.42cvss 6.5epss 0.01

    Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials.

  • CVE-2021-36756MedOct 27, 2021
    risk 0.42cvss 6.5epss 0.00

    CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.

  • CVE-2026-33553MedJun 2, 2026
    risk 0.40cvss 6.1epss 0.00

    Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.

  • CVE-2026-24710MedMay 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.

  • CVE-2019-19394MedApr 16, 2020
    risk 0.40cvss 6.1epss 0.01

    Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0.

  • CVE-2021-44216MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.00

    Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.

  • CVE-2021-44215MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.00

    Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.

  • CVE-2021-38379MedOct 27, 2021
    risk 0.36cvss 5.5epss 0.00

    The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.