CVE-2024-28987 - SolarWinds Web Help Desk Hardcoded Credential Vulnerability
Project:SolarWinds
Product:Web Help Desk
Date Added:2024-10-15Due Date:2024-11-05
Vulnerability Name
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
Description
SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28987
https://nvd.nist.gov/vuln/detail/CVE-2024-28987
Related News Articles
SolarWinds Web Help Desk flaw is now exploited in attacksOctober 17, 2024
CISA Warns of Active Exploitation in SolarWinds Help Desk Software VulnerabilityOctober 16, 2024