The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
https://www.theregister.com/2024/08/22/hardcoded_credentials_bug_solarwinds_whd/
https://www.bleepingcomputer.com/news/security/solarwinds-web-help-desk-flaw-is-now-exploited-in-attacks/
https://thehackernews.com/2024/10/cisa-warns-of-active-exploitation-in.html
https://arcticwolf.com/resources/blog/cve-2024-28988/
https://www.bleepingcomputer.com/news/security/solarwinds-fixes-hardcoded-credentials-flaw-in-web-help-desk/
https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28987
https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2
Source: Mitre, NVD
Published: 2024-08-21
Updated: 2024-11-29
Known Exploited Vulnerability (KEV)
Base Score: 9.4
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N
Severity: High
Base Score: 9.1
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity: Critical
EPSS: 0.94221