CVE-2022-32290 describes an Incorrect Access Control vulnerability in Northern.tech Mender client versions 3.2.0, 3.2.1, and 3.2.2. The client's HTTP proxy, intended for local API calls, improperly listens on all network interfaces instead of only localhost. This allows any client on the same network to connect to the proxy and forward requests to the Mender Server, potentially bypassing mTLS authentication if configured. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-adjacent attack vector with low complexity and no user interaction required. While it doesn't directly expose sensitive data, it increases the attack surface and could be a stepping stone for exploiting other vulnerabilities on the client or server. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low awareness or perceived threat at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.2.0CPE matchmatch criteria | cpe:2.3:a:northern.tech:mender:3.2.0:*:*:*:-:*:*:* | ||
3.2.1CPE matchmatch criteria | cpe:2.3:a:northern.tech:mender:3.2.1:*:*:*:-:*:*:* | ||
3.2.2CPE matchmatch criteria | cpe:2.3:a:northern.tech:mender:3.2.2:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.