VDB
CVE-2024-28987
CVE-2024-28987
PUBLISHED
KEV
CVSS 9.100000381469727 CRITICAL
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
EPSS 94.29% · 99.9th percentile
Risk Scores
CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
94.29%
99.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SolarWinds | Web Help Desk | 12.8.3 Hotfix 1 and previous versions, 12.8.3 Hotfix 1 and previous versions |
| solarwinds | web_help_desk | 12.8.3, 0, 12.8.3 |
| solarwinds | webhelpdesk | 0, 0 |
Timeline
- Aug 21, 2024 CVE Published
- Aug 22, 2024 EPSS Score
- Aug 22, 2024 PoC Published
- Aug 22, 2024 PoC Published
- Aug 22, 2024 PoC Published
- Aug 23, 2024 PoC Published
- Sep 5, 2024 EPSS Score
- Sep 5, 2024 PoC Published
- Sep 5, 2024 PoC Published
- Sep 5, 2024 PoC Published
- Sep 5, 2024 PoC Published
- Sep 5, 2024 PoC Published
References
- https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28987 url
- https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2 url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-28987 url
- https://www.theregister.com/2024/08/22/hardcoded_credentials_bug_solarwinds_whd/ url
- https://nvd.nist.gov/vuln/detail/CVE-2024-28987 advisory
- https://www.theregister.com/2024/08/22/hardcoded_credentials_bug_solarwinds_whd url