← Back

Wise Paas/rmm

wise-paas/rmm

Vendor: Advantech • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Advantech
1Wise Paas/rmm
Jun 17, 2026
May 7, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafana APIs. Authenticat...Show more
The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafana APIs. Authentication is not required for exploitation on the WISE-PaaS/RMM (versions prior to 9.0.1).Show less
1Advantech
1Wise Paas/rmm
Jun 17, 2026
Oct 31, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Lack of sanitization of user-supplied input cause SQL injection vulnerabilities. An attacker can leverage these vulnerabilities to disclose information.
1Advantech
1Wise Paas/rmm
Jun 17, 2026
Oct 31, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclosure of sensitive data.
1Advantech
1Wise Paas/rmm
Jun 17, 2026
Oct 31, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage these vulnera...Show more
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage these vulnerabilities to remotely execute code while posing as an administrator.Show less
1Advantech
1Wise Paas/rmm
Jun 17, 2026
Oct 31, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication.