CVE-2023-26462

ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) are stored in an insecure format. (To read this stored data, the attacker needs access to the application server or its source code.)
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:thingsboard:thingsboard:3.4.1:*:*:*:*:*:*:*

History

03 Mar 2023, 02:29

Type Values Removed Values Added
CWE CWE-798
CPE cpe:2.3:a:thingsboard:thingsboard:3.4.1:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/238544 - (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/238544 - Third Party Advisory, VDB Entry
References (MISC) https://thingsboard.io/docs/reference/releases/ - (MISC) https://thingsboard.io/docs/reference/releases/ - Release Notes

23 Feb 2023, 14:19

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-23 06:15

Updated : 2024-02-04 23:14


NVD link : CVE-2023-26462

Mitre link : CVE-2023-26462

CVE.ORG link : CVE-2023-26462


JSON object : View

Products Affected

thingsboard

  • thingsboard
CWE
CWE-798

Use of Hard-coded Credentials