PT-2021-17450 · Unknown+1 · Wise-Paas/Rmm+1

Chizuru Toyama

·

Published

2021-05-07

·

Updated

2021-05-19

·

CVE-2021-27437

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WISE-PaaS/RMM versions prior to 9.0.1
Description The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafana APIs. Authentication is not required for exploitation.
Recommendations For versions prior to 9.0.1, update to version 9.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Grafana APIs to minimize the risk of exploitation. Avoid using the hard-coded administrator username and password until the issue is resolved.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27437

Affected Products

Grafana
Wise-Paas/Rmm