Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Northern.Tech

First CVE: Apr 16, 2020Active for: 6 yearsTotal CVEs: 15
23.1
VTI Score
Low

Northern.Tech maintains a modest portfolio of infrastructure and device-management tools, including configuration-management, OS update, and user-administration products that operate in privileged or trust-boundary positions within enterprise environments. Its vulnerability profile centers on access-control and input-handling weaknesses—including improper default permissions, access-control flaws, cross-site scripting, cross-site request forgery, and certificate-validation issues—that recur across its product line and reflect the authentication and web-interface demands of management-tier software. Defenders should prioritize patch deployment for these products given their administrative access scope; current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Northern.Tech over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 16, 2020
6 years ago
Most Recent CVE
May 14, 2026
71 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-29556CRITICAL
The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execu
Apr 28, 20229.829NONO
CVE-2026-24712HIGH
Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.
May 14, 20267.327NONO
CVE-2022-29555HIGH
The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking.
Apr 28, 20228.827NONO
CVE-2026-24710MEDIUM
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.
May 14, 20266.123NONO
CVE-2023-45684HIGH
Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission
Nov 14, 20237.522NONO
CVE-2021-35342HIGH
The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the sys
Aug 27, 20217.522NONO
CVE-2026-24711MEDIUM
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.
May 14, 20265.321NONO
CVE-2023-26560MEDIUM
Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover cr
Apr 26, 20236.521NONO
CVE-2021-36756MEDIUM
CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.
Oct 27, 20216.521NONO
CVE-2021-44215MEDIUM
Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.
Mar 10, 20225.520NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
67%
27%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (20.0%)
Network11 (73.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.7%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (80.0%)
Unknown0 (0.0%)
Required3 (20.0%)
Privileges Required
Low5 (33.3%)
High0 (0.0%)
None10 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Northern.Tech.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Northern.Tech — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Northern.Tech's Products

View all 1 CNAs →

Top CWEs