Vulnerability Description
The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafana APIs. Authentication is not required for exploitation on the WISE-PaaS/RMM (versions prior to 9.0.1).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Advantech | Wise-Paas\/Rmm | < 9.0.1 |
Related Weaknesses (CWE)
References
- https://us-cert.cisa.gov/ics/advisories/icsa-21-124-01Third Party AdvisoryUS Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-21-124-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2021-27437?
CVE-2021-27437 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafa...
How severe is CVE-2021-27437?
CVE-2021-27437 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-27437?
Check the references section above for vendor advisories and patch information. Affected products include: Advantech Wise-Paas\/Rmm.