CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2024-28987

CVSS 9.1v3.1pub. 2024-08-21upd. 2025-10-27

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

🤖 AI Analysis
How it works

In SolarWinds WHD software, hardcoded credentials embedded in the source code allow an attacker to bypass authorization mechanisms without knowledge of any administrative passwords. An attacker can connect remotely over the network, authenticate using these built-in credentials, and gain access to internal application functionality. No user interaction or prior privileges are required.

Impact

An attacker can gain unauthorized access to internal Help Desk system functions and modify stored data, which may lead to violations of confidentiality and integrity of information processed by the system.

Mitigation & patch

The SolarWinds Web Help Desk 12.8.3 Hotfix 2 patch should be applied immediately, available at the SolarWinds support center. Due to active vulnerability exploitation, the update should be deployed immediately.

Who is affected

SolarWinds Web Help Desk (WHD) — versions specified in vendor references; patch available in version 12.8.3 Hotfix 2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Solarwinds Web Help Desk

    APP
    Solarwinds
    12.8.3< 12.8.3

CISA KEV — detailsi

Vendori
SolarWinds
Producti
Web Help Desk
Added to KEVi
October 15, 2024
Remediation deadline (US Federal)i
November 5, 2024(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 5 listopada 2024
CWE
References

Related vulnerabilities

CVE-2025-40551CRITICAL9.8⚠ KEVPL ✓same product

RCE przez deserializację w SolarWinds Web Help Desk — bez uwierzytelnienia

CVE-2025-26399CRITICAL9.8⚠ KEVPL ✓same product

RCE przez deserializację AjaxProxy w SolarWinds Web Help Desk (nieuwierzytelniony)

CVE-2024-28986CRITICAL9.8⚠ KEVPL ✓same product

RCE przez Java Deserialization w SolarWinds Web Help Desk

CVE-2026-28323CRITICAL9.8PL ✓same product

SolarWinds Web Help Desk — pominięcie uwierzytelnienia SAML 2.0

CVE-2025-40552CRITICAL9.8PL ✓same product

SolarWinds Web Help Desk — pominięcie uwierzytelnienia (Auth Bypass)