The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
In SolarWinds WHD software, hardcoded credentials embedded in the source code allow an attacker to bypass authorization mechanisms without knowledge of any administrative passwords. An attacker can connect remotely over the network, authenticate using these built-in credentials, and gain access to internal application functionality. No user interaction or prior privileges are required.
An attacker can gain unauthorized access to internal Help Desk system functions and modify stored data, which may lead to violations of confidentiality and integrity of information processed by the system.
The SolarWinds Web Help Desk 12.8.3 Hotfix 2 patch should be applied immediately, available at the SolarWinds support center. Due to active vulnerability exploitation, the update should be deployed immediately.
SolarWinds Web Help Desk (WHD) — versions specified in vendor references; patch available in version 12.8.3 Hotfix 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NSolarwinds Web Help Desk
APPSolarwinds12.8.3< 12.8.3
CISA KEV — detailsi
- Vendori
- SolarWinds
- Producti
- Web Help Desk
- Added to KEVi
- October 15, 2024
- Remediation deadline (US Federal)i
- November 5, 2024(overdue)
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.
Related vulnerabilities
RCE przez deserializację w SolarWinds Web Help Desk — bez uwierzytelnienia
RCE przez deserializację AjaxProxy w SolarWinds Web Help Desk (nieuwierzytelniony)
RCE przez Java Deserialization w SolarWinds Web Help Desk
SolarWinds Web Help Desk — pominięcie uwierzytelnienia SAML 2.0
SolarWinds Web Help Desk — pominięcie uwierzytelnienia (Auth Bypass)