// For flags

CVE-2024-28987

SolarWinds Web Help Desk Hardcoded Credential Vulnerability

Severity Score

9.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

6
*Multiple Sources

Exploited in Wild

Yes
*KEV

Decision

Act
*SSVC
Descriptions

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.

*Credits: Zach Hanley
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Act
Exploitation
Active
Automatable
Yes
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2024-03-13 CVE Reserved
  • 2024-08-21 CVE Published
  • 2024-09-05 First Exploit
  • 2024-10-15 Exploited in Wild
  • 2024-10-16 CVE Updated
  • 2024-11-05 KEV Due Date
  • 2025-02-01 EPSS Updated
CWE
  • CWE-798: Use of Hard-coded Credentials
CAPEC
  • CAPEC-21: Exploitation of Trusted Identifiers
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Solarwinds
Search vendor "Solarwinds"
Web Help Desk
Search vendor "Solarwinds" for product "Web Help Desk"
*-
Affected
Solarwinds
Search vendor "Solarwinds"
Webhelpdesk
Search vendor "Solarwinds" for product "Webhelpdesk"
*-
Affected