Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
thingsboard thingsboard 3.4.1 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-40004
Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote malicious users to escalate privilege via crafted URL to the Audit Log.
Thingsboard Thingsboard 3.4.1
NA
CVE-2023-26462
ThingsBoard 3.4.1 could allow a remote malicious user to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) are stored in an insecure format. (To read this stored data, the attacker needs access to the application server or its sourc...
Thingsboard Thingsboard 3.4.1
NA
CVE-2022-48341
ThingsBoard 3.4.1 could allow a remote authenticated malicious user to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by modifying the scope via the scopes parameter.
Thingsboard Thingsboard 3.4.1
NA
CVE-2022-45608
An issue exists in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and become an Administrator (TENANT_ADMIN) or (SYS_ADMIN) on the web application. It is important to note that in order to accomplish this, the attacker...
Thingsboard Thingsboard 3.4.1
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5834
CVE-2024-30100
CVE-2024-4577
physical
dos
CVE-2024-30099
CVE-2024-27801
CVE-2024-32146
logic flaw
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started