Vulnerability Description
The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal API endpoints.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Northern.Tech | Mender | 3.2.0 |
Related Weaknesses (CWE)
References
- https://mender.io/blog/cve-2022-29555-and-cve-2022-29556-vulnerabilities-in-iot-Vendor Advisory
- https://northern.techVendor Advisory
- https://mender.io/blog/cve-2022-29555-and-cve-2022-29556-vulnerabilities-in-iot-Vendor Advisory
- https://northern.techVendor Advisory
FAQ
What is CVE-2022-29556?
CVE-2022-29556 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant acti...
How severe is CVE-2022-29556?
CVE-2022-29556 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-29556?
Check the references section above for vendor advisories and patch information. Affected products include: Northern.Tech Mender.