TROYANOSYVIRUS
Voltar para CVEs

CVE-2024-28986

CRITICALCISA KEV
9.8

Descricao

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing.   However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available.

Detalhes CVE

Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado8/13/2024
Ultima modificacao10/27/2025
Fontekev
Avistamentos honeypot0

CISA KEV

FornecedorSolarWinds
ProdutoWeb Help Desk
Nome da vulnerabilidadeSolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
Data inclusao KEV2024-08-15
Prazo de remediacao2024-09-05
Uso em ransomwareUnknown

Produtos afetados

solarwinds:web_help_desk

Fraquezas (CWE)

CWE-502

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.