Описание
The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafana APIs. Authentication is not required for exploitation on the WISE-PaaS/RMM (versions prior to 9.0.1).
Ссылки
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 9.0.1 (исключая)
cpe:2.3:a:advantech:wise-paas\/rmm:*:*:*:*:*:*:*:*
EPSS
Процентиль: 39%
0.00174
Низкий
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-798
Связанные уязвимости
github
больше 3 лет назад
The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafana APIs. Authentication is not required for exploitation on the WISE-PaaS/RMM (versions prior to 9.0.1).
EPSS
Процентиль: 39%
0.00174
Низкий
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-798