Junglewise Threat Intelligence

CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability

CVE-2024-28987 · Severity: critical · CVSS 9.1 · Exploited in the wild · Published 2024-10-15

Executive brief

SolarWinds Web Help Desk (WHD) contains a hardcoded credential vulnerability. A remote, unauthenticated attacker can exploit this to access internal functionality and modify sensitive data.

Affected products

  • SolarWinds Web Help Desk (WHD) Up to (excluding) 12.8.3 Hotfix 2

Timeline

  • 2024-08-21: disclosed: Initial CVE publication and vendor advisory
  • 2024-10-15: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
  • 2024-10-15: exploited: Reported as exploited in the wild

Related threats