LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 15, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 5, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-28987 to its Known Exploited Vulnerabilities catalog on Oct 15, 2024, with a federal patch deadline of Nov 5, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.

CVE-2024-28987 is a hardcoded credential vulnerability in SolarWinds Web Help Desk. According to CISA, it could allow a remote, unauthenticated user to access internal functionality and modify data.

Help desk platforms commonly store ticket details, user accounts, and integration credentials. Unauthorized access of this kind can let an attacker alter records or pivot into connected systems, so teams that run the product should treat the issue as high priority and confirm all details against the vendor advisory.

How it works

The weakness is classified as CWE-798: use of hard-coded credentials. In this class of flaw, authentication material is embedded directly in the software rather than being supplied or rotated by the administrator. An attacker who learns or extracts those fixed credentials can present them to the application without any prior authentication.

Once accepted, the credentials grant access to internal functionality that would normally be protected. The CISA summary states that this can result in data modification. Exact credential values, endpoints, or request formats are not provided here; defenders must obtain those specifics from the vendor advisory and treat any public claims of exploit code with caution until verified.

Am I affected? How to find it in your systems

SolarWinds Web Help Desk is typically deployed as a web application on Windows or Linux servers that support IT service desks. It may be internet-facing or reachable only from internal networks, and it often integrates with directory services, email, and asset databases.

Inventory steps:

Because exact affected version ranges are not listed in the supplied facts, compare every discovered instance against the vendor advisory to determine whether it is vulnerable. Also examine authentication and application logs for unexpected successful logins from unauthenticated sources, sudden configuration changes, or bulk data modifications that lack corresponding user tickets. Network telemetry showing unusual traffic to the help-desk host from external or untrusted segments can serve as an additional indicator.

How to remediate

The primary action is to apply the mitigations or updates published by the vendor. CISA’s required action is to follow those vendor instructions or to discontinue use of the product if mitigations are unavailable. After patching, restart services as directed and verify that the hard-coded credential path is no longer reachable.

For this class of weakness, also:

Document the remediation date and retain evidence for compliance or incident-response purposes.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These steps lower risk but do not eliminate it; schedule the permanent fix promptly.

If your data may have been exposed

Actively exploited vulnerabilities of this type frequently lead to data breaches. If logs or other evidence suggest the hard-coded credentials were used, treat the incident as a potential compromise of ticket data and any linked systems. Preserve forensic artifacts, reset affected credentials, and follow your organization’s incident-response plan. Separately, individuals can run a free exposure scan of their email address against known breach data sets to check whether personal information has already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSolarWinds · Web Help Desk
WeaknessCWE-798
Added to CISA KEVOct 15, 2024
Federal patch deadlineNov 5, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities