EXPOSURES › CVE-2024-28987
CVE-2024-28987
HIGH ⌖ ON CISA KEV · EXPLOITEDSolarWinds Web Help Desk allows remote unauthenticated access via hardcoded credentials, enabling data modification.
SolarWinds Web Help Desk contains a hardcoded credential vulnerability that permits remote, unauthenticated users to access internal functionality and modify data. This failure exposes DIB organizations to unauthorized data tampering and violates FedRAMP/NIST 800-171 requirements for secure configuration and access control. Defense contractors must audit all SolarWinds assets and enforce credential rotation policies immediately.
Shame score — Hardcoded credentials in a widely deployed help desk tool represent a negligent security practice that directly enables unauthorized access and data modification.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.