CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.1. It may be remotely exploitable.
CVE
CVE-2023-26462
Severity
HIGH
CVSS
8.1
EPSS
1.13%
Original NVD Description
ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) are stored in an insecure format. (To read this stored data, the attacker needs access to the application server or its source code.)
Related CVEs
Other vulnerabilities affecting the same vendor(s)