The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
Solution:
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28987 | vendor advisory |
https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2 | release notes |
https://www.theregister.com/2024/08/22/hardcoded_credentials_bug_solarwinds_whd/ | press/media coverage third party advisory |