logo

SolarWinds left critical hardcoded credentials in its Web Help Desk product

ID: c1dcc027-645f-53ff-9db6-8cddf213bcd0

STIX ID: report--c1dcc027-645f-53ff-9db6-8cddf213bcd0

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-08-22

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

SolarWinds Web Help Desk contains a critical hardcoded-credentials vulnerability (CVE-2024-28987, CVSS 9.1) affecting versions up to 12.8.3 HF1; SolarWinds released hotfix 12.8.3 HF2 which must be manually applied. The report urges rapid patching due to likely internet-facing scanning and potential exploitation across government and enterprise customers, and also notes a separate critical Java deserialization RCE (CVE-2024-28986, CVSS 9.8) recently highlighted by CISA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.