Critical severity9.1NVD Advisory· Published May 7, 2021· Updated Jun 17, 2026
CVE-2021-27437
CVE-2021-27437
Description
The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafana APIs. Authentication is not required for exploitation on the WISE-PaaS/RMM (versions prior to 9.0.1).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:advantech:wise-paas\/rmm:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:advantech:wise-paas\/rmm:*:*:*:*:*:*:*:*range: <9.0.1
- (no CPE)range: <9.0.1
- WISE-PaaS/WISE-PaaS/RMMdescription
Patches
Vulnerability mechanics
References
1- us-cert.cisa.gov/ics/advisories/icsa-21-124-01nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.