VDB
CVE-2024-28986
CVE-2024-28986
PUBLISHED
KEV
CVSS 9.800000190734863 CRITICAL
Une vulnérabilité a été découverte dans SolarWinds Web Help Desk. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.
EPSS 81.46% · 99.2th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
81.46%
99.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| solarwinds | web_help_desk | 0, 12.8.3 |
| solarwinds | webhelpdesk | 0 |
| SolarWinds | Web Help Desk | previous versions |
Timeline
- Aug 13, 2024 CVE Published
- Aug 14, 2024 EPSS Score
- Aug 15, 2024 CISA KEV Added
- Aug 15, 2024 PoC Published
- Aug 16, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Feb 23, 2025 PoC Published
- Mar 17, 2025 EPSS Score
- Mar 19, 2025 EPSS Score
- Mar 27, 2025 EPSS Score
- Mar 28, 2025 EPSS Score
- Mar 29, 2025 EPSS Score
References
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28986 url
- https://support.solarwinds.com/SuccessCenter/s/article/WHD-12-8-3-Hotfix-1 url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-28986 url
- https://nvd.nist.gov/vuln/detail/CVE-2024-28986 advisory
- https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28986 advisory