Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6h82-hhr3-9q29

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafana APIs. Authentication is not required for exploitation on the WISE-PaaS/RMM (versions prior to 9.0.1).

The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafana APIs. Authentication is not required for exploitation on the WISE-PaaS/RMM (versions prior to 9.0.1).

EPSS

Процентиль: 39%
0.00174
Низкий

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 9.1
nvd
почти 5 лет назад

The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafana APIs. Authentication is not required for exploitation on the WISE-PaaS/RMM (versions prior to 9.0.1).

EPSS

Процентиль: 39%
0.00174
Низкий

Дефекты

CWE-798