The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
Advisories

No advisories yet.

Fixes

Solution

SolarWinds recommends that customers upgrade to SolarWinds Web Help Desk v12.8.3 HF2 as soon as it becomes available.


Workaround

No workaround given by the vendor.

History

Fri, 22 Nov 2024 12:00:00 +0000


Wed, 16 Oct 2024 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds web Help Desk
CPEs cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*
cpe:2.3:a:solarwinds:web_help_desk:12.8.3:-:*:*:*:*:*:*
cpe:2.3:a:solarwinds:web_help_desk:12.8.3:hotfix1:*:*:*:*:*:*
Vendors & Products Solarwinds web Help Desk

Wed, 16 Oct 2024 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2024-10-15'}


Thu, 26 Sep 2024 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds webhelpdesk
CPEs cpe:2.3:a:solarwinds:webhelpdesk:*:*:*:*:*:*:*:*
Vendors & Products Solarwinds
Solarwinds webhelpdesk
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 24 Aug 2024 23:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:solarwinds:webhelpdesk:*:*:*:*:*:*:*:*
Vendors & Products Solarwinds
Solarwinds webhelpdesk
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 22 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds webhelpdesk
CPEs cpe:2.3:a:solarwinds:webhelpdesk:*:*:*:*:*:*:*:*
Vendors & Products Solarwinds
Solarwinds webhelpdesk
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 21 Aug 2024 21:30:00 +0000

Type Values Removed Values Added
Description The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
Title SolarWinds Web Help Desk Hardcoded Credential Vulnerability
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2025-07-30T01:36:34.624Z

Reserved: 2024-03-13T20:27:09.782Z

Link: CVE-2024-28987

cve-icon Vulnrichment

Updated: 2024-08-24T22:45:30.565Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-21T22:15:04.350

Modified: 2024-11-29T16:34:47.650

Link: CVE-2024-28987

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.