Impact
Northern.tech Mender Client 5 versions before 5.0.4 contain a flaw that allows an attacker to bypass the client's cryptographic signature verification. This means the client may accept software updates that have not been properly authenticated, potentially enabling the installation of tampered or malicious packages on the device.
Affected Systems
Devices running Mender Client 5 with a version earlier than 5.0.4 are affected. Any such installation that accepts updates from an attacker‑controlled or compromised update source is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, so no known active exploits are reported. The most likely attack vector is through the update distribution channel, where a compromised update server or a malicious update package could be delivered. The overall risk is moderate; mitigating the vulnerability is recommended.
OpenCVE Enrichment