CVE-2023-26462

ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) are stored in an insecure format. (To read this stored data, the attacker needs access to the application server or its source code.)
Configurations

Configuration 1 (hide)

cpe:2.3:a:thingsboard:thingsboard:3.4.1:*:*:*:*:*:*:*

History

21 Nov 2024, 07:51

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/238544 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/238544 - Third Party Advisory, VDB Entry
References () https://thingsboard.io/docs/reference/releases/ - Release Notes () https://thingsboard.io/docs/reference/releases/ - Release Notes

03 Mar 2023, 02:29

Type Values Removed Values Added
References (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/238544 - (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/238544 - Third Party Advisory, VDB Entry
References (MISC) https://thingsboard.io/docs/reference/releases/ - (MISC) https://thingsboard.io/docs/reference/releases/ - Release Notes
CWE CWE-798
CPE cpe:2.3:a:thingsboard:thingsboard:3.4.1:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

23 Feb 2023, 14:19

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-23 06:15

Updated : 2024-11-21 07:51


NVD link : CVE-2023-26462

Mitre link : CVE-2023-26462

CVE.ORG link : CVE-2023-26462


JSON object : View

Products Affected

thingsboard

  • thingsboard
CWE
CWE-798

Use of Hard-coded Credentials