← Voltar para CVEs
CVE-2024-28986
CRITICALCISA KEV9.8
Descricao
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing. However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available.
Detalhes CVE
Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado8/13/2024
Ultima modificacao10/27/2025
Fontekev
Avistamentos honeypot0
CISA KEV
FornecedorSolarWinds
ProdutoWeb Help Desk
Nome da vulnerabilidadeSolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
Data inclusao KEV2024-08-15
Prazo de remediacao2024-09-05
Uso em ransomwareUnknown
Produtos afetados
solarwinds:web_help_desk
Fraquezas (CWE)
CWE-502
Referencias
https://support.solarwinds.com/SuccessCenter/s/article/WHD-12-8-3-Hotfix-1(psirt@solarwinds.com)
https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28986(psirt@solarwinds.com)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-28986(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.