Impact
The vulnerability is a directory traversal flaw that allows an attacker to alter file path parameters passed to the Mender Server, enabling access to files outside the intended directories. This weakness is characterized as CWE-22 (Path Traversal). This can expose confidential files or configuration data and may be exploited to gain further footholds if sensitive information is discovered.
Affected Systems
Northern.tech Mender Server, versions 4.1.0, 4.0.1 and all earlier releases, are affected. The flaw was fixed in revision 4.1.1 and 4.0.2.
Risk and Exploitability
The EPSS score indicates a low exploitation probability of less than 1%, and the CVSS score of 3.1 indicates low severity; the vulnerability is not listed in the CISA KEV catalog, indicating no publicly documented exploits at the time of analysis. Based on the description, the likely attack vector involves sending specially crafted file paths to the vulnerable API endpoint, and directory traversal is a well‑known attack that can be abused with minimal skill if the endpoint is reachable. The absence of public exploitation data does not reduce the potential for internal or targeted attacks, especially if the Mender Server is exposed to untrusted networks.
OpenCVE Enrichment