Mender
Vendor:
First CVE: Aug 27, 2021 · Active for 4 years
5
Total CVEs
More Total CVEs than 77% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mender over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 27, 2021
4 years ago
Most Recent CVE
Nov 8, 2024
625 days ago
CVE Severity & Scoring
Mender5 CVEs
40%
40%
20%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (20.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (80.0%)
Unknown0 (0.0%)
Required1 (20.0%)
Privileges Required
Low1 (20.0%)
High0 (0.0%)
None4 (80.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29556CRITICAL The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execu | Apr 28, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-29555HIGH The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking. | Apr 28, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-35342HIGH The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the sys | Aug 27, 2021 | 7.5 | 22 | NO | NO |
CVE-2022-32290MEDIUM The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivileged TCP port and exposes an HTTP proxy to facilitate API c | Jul 6, 2022 | 4.3 | 17 | NO | NO |
CVE-2024-46948MEDIUM Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control. | Nov 8, 2024 | 4.3 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Mender
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2.2 | 1 | 4.3 | 0.2% | 0 | 0 |
| 3.2.1 | 2 | 7.0 | 0.6% | 0 | 0 |
| 3.2.0 | 2 | 7.0 | 0.6% | 0 | 0 |