ZeroHour

CVE-2024-28987

KEVmoderate1

Hardcoded Credential in SolarWinds Web Help Desk Allows Unauthenticated Access

CISA: SolarWinds Web Help Desk Hardcoded Credential Vulnerability

CVSS 3.1
9.1 critical
EPSS
93%p100
Published
()
KEV added
AI analysis

SolarWinds Web Help Desk (WHD) contains hard-coded credentials (CWE-798): fixed, built-in authentication material embedded in the shipped software. Because the same credentials exist on every WHD installation, a remote attacker who knows them can authenticate to WHD without any user account, with no privileges or user interaction required (CVSS 3.1 9.1, AV:N/AC:L/PR:N/UI:N). Successful use grants access to internal WHD functionality and the ability to modify data, with high confidentiality and integrity impact but no availability impact. Any organization running an unpatched WHD instance is affected, particularly internet-exposed deployments such as those operated by managed service providers and enterprise IT service desks. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-15 (ransomware use not yet reported), EPSS assigns a 93.2% probability of exploitation within 30 days (100th percentile), and no public proof-of-concept was known at the time of this record.

What to do: Upgrade all WHD instances to the patched SolarWinds release that includes the October 2024 fix for CVE-2024-28987 (check the SolarWinds PSIRT advisory for the exact fixed version, e.g., WHD 12.8.4 or later); the required KEV action applies, and U.S. federal agencies must remediate by November 5, 2024. Prioritize internet-exposed WHD servers: restrict network access to the help desk interface/API until patched and review logs for unauthenticated access using built-in credentials, since exploitation is confirmed in the wild. If patching is not possible, apply mitigations per vendor instructions or discontinue use of the product, as CISA recommends.

Affected
SolarWinds Web Help Desk (WHD)unpatched WHD releases at the time of disclosure (CISA lists the affected product as SolarWinds Web Help Desk; no version range is provided in this data — see t
Estimated exposure
moderate≈ a few thousand internet-exposed WHD instances, with total deployments likely in the low tens of thousands worldwide (estimate) — SolarWinds WHD is a specialist IT service-desk product with no public active-install telemetry, so the estimate combines typical public-scan counts of exposed WHD instances (on the order of a few thousand) with its common enterprise/MSP…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

CISA Known Exploited Vulnerability
Affected
SolarWinds Web Help Desk
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
solarwinds
Products
web help desk
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news