CVE-2024-28986 - SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

项目:SolarWinds

产品:Web Help Desk

添加日期:2024-08-15到期日:2024-09-05最后更新:June 21, 2025

漏洞名称

SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

描述

SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution.

已知用于勒索软件活动吗?

Unknown

采集行动

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

其他说明

https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28986

https://nvd.nist.gov/vuln/detail/CVE-2024-28986

相关新闻文章

SolarWinds Fixes Four Critical Web Help Desk Flaws With Unauthenticated RCE and Auth BypassJanuary 29, 2026

SolarWinds fixes critical Web Help Desk RCE vulnerabilities, upgrade ASAP!January 29, 2026

SolarWinds warns of critical Web Help Desk RCE, auth bypass flawsJanuary 28, 2026

SolarWinds fixes critical Web Help Desk RCE vulnerability (CVE-2025-26399)September 24, 2025

SolarWinds Releases Hotfix for Critical CVE-2025-26399 Remote Code Execution FlawSeptember 23, 2025

相关 CWE