Privilege Escalation Vulnerability in ThingsBoard by ThingsBoard
CVE-2023-26462

8.1HIGH

Key Information:

Vendor
CVE Published:
23 February 2023

What is CVE-2023-26462?

A vulnerability in ThingsBoard versions prior to 3.4.1 exposes hard-coded service credentials in an insecure manner, granting remote attackers the opportunity to perform privilege escalation. If they gain access to the application server or its source code, attackers can exploit this weakness to elevate their privileges and potentially access sensitive data or perform unauthorized actions within the system. It is critical for users to secure their applications and review access controls to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.