CISA Warns of Active Exploitation in SolarWinds Help Desk Software Vulnerability
Citing evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a severe security issue affecting SolarWinds Web Help Desk (WHD) software to its list of known exploited vulnerabilities (KEVs).
The vulnerability, identified as CVE-2024-28987 (CVSS score: 9.1), concerns a situation where hard-coded credentials could be misused to obtain unauthorized access and make changes.
According to a CISA advisory, SolarWinds Web Help Desk has a hardcoded credential vulnerability that might let an unauthorized remote user access internal features and change data.
SolarWinds initially revealed the vulnerability in late August 2024, and a month later, cybersecurity company Horizon3.ai released more technical details read more about CISA W...

