Use of hard-coded credentials in Web Help Desk - CVE-2024-28987
Published: August 22, 2024 / Updated: April 25, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain full access to vulnerable system.
The vulnerability exists due to presence of hard-coded credentials in application's code. A remote unauthenticated attacker can access the affected system using the hard-coded credentials.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
How to mitigate CVE-2024-28987
Links to Public Exploits and PoC-codes
- Exploit #11333 - CVE-2024-28987 (Proof of Concept Exploit for CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability) (April 25, 2025)
- Exploit #10944 - CVE-2024-28987-POC (December 6, 2024)
- Exploit #10786 - SolarWinds Web Help Desk Backdoor (CVE-2024-28987) (October 31, 2024)
- Exploit #10561 - CVE-2024-28987 (CVE-2024-28987 Scanner & Exploiter - SolarWinds Web Help Desk) (October 9, 2024)
- Exploit #10540 - CVE-2024-28987 (September 27, 2024)
- Exploit #10499 - CVE-2024-28987-POC (September 6, 2024)