← back
CVE-2021-27437

CVE-2021-27437

EPSS 1.2%CWE-798
The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafana APIs. Authentication is not required for exploitation on the WISE-PaaS/RMM (versions prior to 9.0.1).
Affected products
n/a · WISE-PaaS/RMM

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →