SolarWinds Security Update – 25 August 2024

SolarWinds has released a security update to fix a vulnerability affecting SolarWinds Web Help Desk.

The addressed vulnerability could allow the remote unauthenticated attacker to access internal functionality and modify data on the affected system.

Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2024-28987

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SolarWinds Security Update

References