CVE-2022-45608: High severity ThingsBoard ThingsBoard vulnerability
An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMERUSER) to gain escalated privileges (vertically) and become an Administrator (TENANTADMIN) or (SYSADMIN) on the web application. It is important to note that in order to accomplish this, the attacker must know the corresponding API's parameter (authority : value).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45608?
The severity of CVE-2022-45608 is high with a severity value of 8.8.
What is the affected software version of CVE-2022-45608?
The affected software version of CVE-2022-45608 is ThingsBoard 3.4.1.
How can an attacker exploit CVE-2022-45608?
An attacker with low privileges (CUSTOMER_USER) can exploit CVE-2022-45608 to gain escalated privileges (vertically) and become an Administrator (TENANT_ADMIN) or (SYS_ADMIN).
What should I do if I am using ThingsBoard 3.4.1?
If you are using ThingsBoard 3.4.1, it is recommended to update to a patched version as soon as possible.
Where can I find more information about CVE-2022-45608?
You can find more information about CVE-2022-45608 on the ThingsBoard website and the Wizard32 blog.