KEVIntel
9.1
CVSS
Critical

CVE-2024-28987

PUBLISHED

SolarWinds Web Help Desk Hardcoded Credential Vulnerability

Exploited in the wild PoC available Remote Low complexity No user interaction
Vendor
SolarWinds
Product
Web Help Desk
Published
Aug 21, 2024
EPSS

Description

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

windows cisa nuclei_scanner nessus_scanner

CVSS scores

CVSS v3.1 9.1 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Exploitation status

Exploited in the wild

Recorded 2024-10-15 00:00:00 UTC · Source

Proof of concept available

Recorded 2024-09-24 18:12:38 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Oct 15, 2024

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

horizon3ai/CVE-2024-28987

github · Created 2024-09-24 18:12:38 UTC · 6 stars

Proof of Concept Exploit for CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability

gh-ost00/CVE-2024-28987-POC

github · Created 2024-09-05 09:01:58 UTC · 11 stars

Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Detected by Nessus

  • Proof of Concept Exploit Available

  • Added to KEVIntel

  • Detected by Nuclei