HomeUpdatesSolarWinds: Fixes Critical Vulnerability in Web Help Desk

SolarWinds: Fixes Critical Vulnerability in Web Help Desk

SolarWinds has fixed a critical vulnerability in its Web Help Desk software, which could allow attackers to log in to vulnerable systems with hardcoded credentials.

SolarWinds Web Help Desk

Web Help Desk (WHD) is a popular software , used by many government agencies, large corporations, and healthcare and education organizations.

See also: GitHub: GHES vulnerability allows authentication bypass

The vulnerability is tracked as CVE-2024-28987 and was patched on Wednesday (Web Help Desk 12.8.3 Hotfix 2). Unauthorized attackers can exploit it to gain access to internal functions and modify data on targeted devices.

SolarWinds has not disclosed whether CVE-2024-28987 has been used in attacks.

See also: LiteSpeed ​​Cache vulnerability puts millions of WordPress sites at risk

The company provides detailed instructions on how to install and remove the hotfix, warning administrators to upgrade vulnerable servers to Web Help Desk 12.8.3.1813 or 12.8.3 HF1 before deploying the hotfix. It also recommends backing up all source files before installing the update.

SolarWinds: Fixes Critical Vulnerability in Web Help Desk

It is worth noting that the SolarWinds update itself also includes another Web Help Desk vulnerability (CVE-2024-28986), which was addressed with another hotfix on August 14 and was flagged by CISA as a vulnerability used in attacks.

See also: Google Chrome: Fix for new zero-day vulnerability

These Web Help Desk vulnerabilities highlight the importance of proactive cybersecurity practices and responsible disclosure in today’s digital landscape. Organizations should prioritize updating software , implementing additional security , and regularly assessing their systems for potential vulnerabilities. By following these steps, a more secure and resilient digital world can be created. So stay vigilant and prioritize security in all aspects of your operations!

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS