Impact
Northern.tech Mender Enterprise Server before version 4.1.1 contains an incorrect access control flaw that permits an attacker to bypass intended permissions and access restricted resources. This weakness is classified as improper access control (CWE‑284) and improper authorization (CWE‑269) and can lead to unauthorized disclosure or modification of system data and functions.
Affected Systems
Affected systems include the Mender Enterprise Server product from Northern.tech, specifically any installation running a version earlier than 4.1.1. No other vendors or product lines are impacted according to the provided data.
Risk and Exploitability
The CVSS score of 3.7 indicates a low severity vulnerability, and the EPSS score is less than 1%, implying a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, which further suggests that it is not widely exploited. Nonetheless, the flaw can still be leveraged remotely via exposed APIs, allowing an attacker to gain unauthorized access to the server's resources. These metrics underline the importance of applying the vendor patch or otherwise restricting access to mitigate risks.
OpenCVE Enrichment