Vulnerabilities > CVE-2021-27437 - Unspecified vulnerability in Advantech Wise-Paas/Rmm 3.3.29

047910
CVSS 9.1 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
advantech
critical

Summary

The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafana APIs. Authentication is not required for exploitation on the WISE-PaaS/RMM (versions prior to 9.0.1).

Vulnerable Configurations

Part Description Count
Application
Advantech
2