<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – CFEngine (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/cfengine.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/cfengine-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – CFEngine (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:33 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-24712 – Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24712</guid>
    <pubDate>Thu, 14 May 2026 15:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24712</strong></p>
  <p>Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45684 – Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45684</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45684</guid>
    <pubDate>Tue, 14 Nov 2023 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45684</strong></p>
  <p>Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45684">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9929 – Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9929</guid>
    <pubDate>Thu, 06 Jun 2019 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9929</strong></p>
  <p>Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2004-1701 – Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-1701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-1701</guid>
    <pubDate>Mon, 09 Aug 2004 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2004-1701</strong></p>
  <p>Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitrary code via a long SAUTH command during RSA authentication.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-1701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2003-0849 – Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2003-0849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2003-0849</guid>
    <pubDate>Mon, 17 Nov 2003 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2003-0849</strong></p>
  <p>Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length values, which is trusted by the ReceiveTransaction function when using a buffer provided by the BusyWithConnection function.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2003-0849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2000-0947 – Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-0947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-0947</guid>
    <pubDate>Tue, 19 Dec 2000 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2000-0947</strong></p>
  <p>Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-0947">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
