VDB

CVE-2024-28987

CVE-2024-28987 PUBLISHED KEV CVSS 9.100000381469727 CRITICAL

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

EPSS 94.29% · 99.9th percentile

Risk Scores

CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
94.29%
99.9th percentile

Affected Products

VendorProductVersions
SolarWindsWeb Help Desk12.8.3 Hotfix 1 and previous versions, 12.8.3 Hotfix 1 and previous versions
solarwindsweb_help_desk12.8.3, 0, 12.8.3
solarwindswebhelpdesk0, 0

Timeline

  • Aug 21, 2024 CVE Published
  • Aug 22, 2024 EPSS Score
  • Aug 22, 2024 PoC Published
  • Aug 22, 2024 PoC Published
  • Aug 22, 2024 PoC Published
  • Aug 23, 2024 PoC Published
  • Sep 5, 2024 EPSS Score
  • Sep 5, 2024 PoC Published
  • Sep 5, 2024 PoC Published
  • Sep 5, 2024 PoC Published
  • Sep 5, 2024 PoC Published
  • Sep 5, 2024 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›