CVE-2024-28987
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
9.1
CVSS 3.1
93.3 %
EPSS (current)
2024-10-15
KEV addition
No
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: SolarWinds / Web Help Desk
Published: 2024-08-21 · Due (CISA): 2024-11-05
CWE: CWE-798 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| nuclei | http/cves/2024/CVE-2024-28987.yaml | SolarWinds Web Help Desk - Hardcoded Credential | – |
| metasploit | auxiliary/gather/solarwinds_webhelpdesk_backdoor | auxiliary/gather/solarwinds_webhelpdesk_backdoor | 2024-08-22 |
References only — no downloads or instructions.