logo

SolarWinds fixes hardcoded credentials flaw in Web Help Desk

ID: 4f0e48cc-34a4-5619-ae24-afcd7355e953

STIX ID: report--4f0e48cc-34a4-5619-ae24-afcd7355e953

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-08-22

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

SolarWinds released a hotfix for Web Help Desk to address a critical authentication bypass (CVE-2024-28987) that allows unauthenticated logins using hardcoded credentials and also bundled a fix for a previously disclosed and actively exploited RCE (CVE-2024-28986); CISA has added the RCE to its KEV catalog and federal agencies were ordered to patch. The advisory urges admins to upgrade to specified hotfix versions and back up original files before applying updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.