CyberRota Analysis
AI-GeneratedA Broken Access Control vulnerability in ThingsBoard Professional Edition (PE) versions 4.21 and below allows authenticated users to manipulate API request parameters related to alarm comments. This exploitation can lead to unauthorized impersonation of system messages and modification of trusted data, resulting in vertical privilege escalation and potential integrity violations. Organizations using affected versions should prioritize remediation to safeguard against unauthorized access and data integrity issues.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate the respective API request parameters to create or modify system-generated alarm comments. This allows unauthorized impersonation of system messages and modification of trusted system-owned data, resulting in vertical privilege escalation and potential integrity violations.