# Impact of certain CVEs on Mender

**URL:** <https://hub.mender.io/t/impact-of-certain-cves-on-mender/4003>\
**Category:** General Discussions\
**Tags:** yocto, security, dunfell\
**Created:** [August 16, 2021, 6:29am UTC](https://hub.mender.io/t/impact-of-certain-cves-on-mender/4003 "2021-08-16T06:29:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![deffo](https://avatars.discourse-cdn.com/v4/letter/d/ec9cab/32.png) [@deffo](https://hub.mender.io/u/deffo)\
**Post date:** [August 16, 2021, 6:29am UTC](https://hub.mender.io/t/impact-of-certain-cves-on-mender/4003/1 "2021-08-16T06:29:00Z")

</div>

Hi there!

How do you consider the impact of

[https://nvd.nist.gov/vuln/detail/CVE-2021-33195](https://nvd.nist.gov/vuln/detail/CVE-2021-33195)  
[https://nvd.nist.gov/vuln/detail/CVE-2021-33196](https://nvd.nist.gov/vuln/detail/CVE-2021-33196)  
[https://nvd.nist.gov/vuln/detail/CVE-2021-33197](https://nvd.nist.gov/vuln/detail/CVE-2021-33197)  
[https://nvd.nist.gov/vuln/detail/CVE-2021-33198](https://nvd.nist.gov/vuln/detail/CVE-2021-33198)

on Mender?

Do you think this is critical? We are asking since dunfell is directly affected with version 1.14.12.

Best regards

---

<div class="post-metadata">

**Author:** ![kacf](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/kacf/32/146_2.png) [@kacf](https://hub.mender.io/u/kacf)\
**Post date:** [August 16, 2021, 7:33am UTC](https://hub.mender.io/t/impact-of-certain-cves-on-mender/4003/2 "2021-08-16T07:33:19Z")

</div>

Taking each one separately:

> [@deffo](#):
>
> [NVD - CVE-2021-33195](https://nvd.nist.gov/vuln/detail/CVE-2021-33195)

I believe it is impacted, but since the client validates the server certificate against the DNS name, in practice it has no other effect than not being able to connect (as long as the attack is going on).

> [@deffo](#):
>
> [NVD - CVE-2021-33196](https://nvd.nist.gov/vuln/detail/CVE-2021-33196)

Impacted, but the attacker must have deployment privileges on the server in order to exploit it. As far as I can tell, all they can do is crash the client, but systemd is set to automatically restart the mender client if it panics, so it should have no lasting effect.

> [@deffo](#):
>
> [NVD - CVE-2021-33197](https://nvd.nist.gov/vuln/detail/CVE-2021-33197)

Not impacted, ReverseProxy is not used in the client.

> [@deffo](#):
>
> [NVD - CVE-2021-33198](https://nvd.nist.gov/vuln/detail/CVE-2021-33198)

I think not impacted, the client doesn’t use the `math.big` package. I’m not 100% sure if some of the crypto functions might use it, but probably this would have been mentioned in the CVE, so I don’t think so.

---

<div class="post-metadata">

**Author:** ![deffo](https://avatars.discourse-cdn.com/v4/letter/d/ec9cab/32.png) [@deffo](https://hub.mender.io/u/deffo)\
**Post date:** [August 16, 2021, 7:58am UTC](https://hub.mender.io/t/impact-of-certain-cves-on-mender/4003/3 "2021-08-16T07:58:52Z")

</div>

Thanks for your quick reply.
