CVE-2024-28987

CVE Published 2024-08-21
Related CWE(s) CWE-798: Use of Hard-coded Credentials
Related Vendor(s) solarwinds
Related Product(s) web_help_desk
Exploitation Reported (CISA KEV) 2024-10-15
CVSS 3 Base Score 9.1 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References