SolarWinds Web Help Desk Vulnerability Enables Unauthenticated RCE

SolarWinds has released an urgent security advisory for a critical vulnerability in its Web Help Desk software that could allow an unauthenticated attacker to achieve remote code execution (RCE).

Cyber Security News
PoC Released for SolarWinds Web Help Desk Vulnerability Exposing Passwords

A Proof-of-Concept (PoC) has been released for a significant vulnerability discovered in SolarWinds Web Help Desk.

GBHackers Security | #1 Globally Trusted Cyber Security News Platform

#SolarWinds has released software updates to fix a critical vulnerability in its #WebHelpDesk software

The vulnerability is tracked as CVE-2024-28987, and when exploited, allows an attacker to access internal functionality and modify data

Administrators are advised to patch ASAP

#cybersecurity #vulnerabilitymanagement

https://www.bleepingcomputer.com/news/security/solarwinds-fixes-hardcoded-credentials-flaw-in-web-help-desk/

SolarWinds fixes hardcoded credentials flaw in Web Help Desk

SolarWinds has released a hotfix for a critical Web Help Desk vulnerability that allows attackers to log into unpatched systems using hardcoded credentials.

BleepingComputer