Critical severity9.1CISA KEVNVD Advisory· Published Aug 21, 2024· Updated Jun 17, 2026
CVE-2024-28987
CVE-2024-28987
Description
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*range: <12.8.3
- cpe:2.3:a:solarwinds:web_help_desk:12.8.3:-:*:*:*:*:*:*
- cpe:2.3:a:solarwinds:web_help_desk:12.8.3:hotfix1:*:*:*:*:*:*
- (no CPE)range: 12.8.3 Hotfix 1 and previous versions
Patches
Vulnerability mechanics
References
4- www.solarwinds.com/trust-center/security-advisories/cve-2024-28987nvdVendor Advisory
- www.theregister.com/2024/08/22/hardcoded_credentials_bug_solarwinds_whd/nvdPress/Media CoverageThird Party Advisory
- support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2nvdRelease Notes
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.