CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability
SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.
Other sources
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Web Help Deskto a version that resolves this vulnerability.Fixed in v12.8.3 HF2 - Compensating control
Discontinue use of SolarWinds Web Help Desk if vendor mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28987?
CVE-2024-28987 has a high severity rating due to its potential for unauthorized remote access and data modification.
How do I fix CVE-2024-28987?
To fix CVE-2024-28987, users should update SolarWinds Web Help Desk to the latest version that addresses the hardcoded credential vulnerability.
What impact does CVE-2024-28987 have on SolarWinds Web Help Desk?
CVE-2024-28987 allows remote, unauthenticated users to access internal functionality, potentially compromising sensitive data.
Which versions of SolarWinds Web Help Desk are affected by CVE-2024-28987?
CVE-2024-28987 affects SolarWinds Web Help Desk versions up to 12.8.3, including 12.8.3-hotfix1.
Is a user authentication required to exploit CVE-2024-28987?
No, CVE-2024-28987 can be exploited by remote, unauthenticated users.