Mender blog

CVE-2022-29555 & CVE-2022-29556 - vulnerabilities in iot-manager and deviceconnect

We recently discovered two vulnerabilities in Mender, thanks to the security researchers April Chaire, Jeff Hofmann, Joey Perme, Nathaniel Singer and Matteo Tarbet, and we have now fixed them.

The deviceconnect microservice in Mender before version 3.2.2 allows Cross-Origin WebSocket Hijacking. The vulnerability is present in the following versions of the product: 2.6.x, 2.7.x, 3.0.x, 3.1.x, 3.2.0, 3.2.1. The vulnerability was patched in Mender 3.2.2. In the official public CVE registry, the issue's ID is CVE-2022-29555.

The iot-manager microservice Mender before version 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal API endpoints. The vulnerability is present in the following versions of the product: 3.2.0, 3.2.1. The vulnerability was patched in Mender 3.2.2. In the official public CVE registry, the issue's ID is CVE-2022-29556.

The security of the Mender product and our users is something we take very seriously. We will continue to look for, fix and responsibly disclose serious weaknesses in our product(s). If you have any questions or concerns, please get in touch with the Mender support if you have a support contract or email security@northern.tech.

Recent articles

New Release – Hosted Mender 4.2.0: Stronger account security and a refreshed management experience

New Release – Hosted Mender 4.2.0: Stronger account security and a refreshed management experience

Discover the latest updates in Hosted Mender 4.2.0, featuring enhanced security, unified login options, and improved device management for IoT solutions.
New in Mender: Introducing support for Yocto 6.0 Wrynose LTS

New in Mender: Introducing support for Yocto 6.0 Wrynose LTS

Mender introduces support for Yocto 6.0 Wrynose LTS, updating components and enhancing compatibility. Discover the latest features and improvements for seamless IoT updates.
Industry insights from STMicroelectronics and Northern.tech

An expert Q&A session on the EU Cyber Resilience Act: Industry insights from STMicroelectronics and Northern.tech

Explore expert insights on the EU Cyber Resilience Act, its implications for IoT products, and essential compliance strategies from industry leaders.
View more articles

Learn why leading companies choose Mender

Discover how Mender empowers both you and your customers with secure and reliable over-the-air updates for IoT devices. Focus on your product, and benefit from specialized OTA expertise and best practices.

 
sales-pipeline_295756365