
A critical vulnerability, CVE-2024-28987, has been disclosed by Horizon3Attack, affecting SolarWinds Web Help Desk. This hardcoded credential vulnerability allows remote attackers to read all help desk tickets, which often contain sensitive IT procedures such as user onboarding, password resets, and shared resource credentials. The proof of concept (PoC) for this vulnerability has been released by Horizon3ai, highlighting the potential risks for IT help desks used by various sectors, including government, education, and small to medium-sized businesses.
Security Upgrades Available for 3 HPE Aruba Networking Bugs https://t.co/qXgtsrmBVf
Critical WhatsUp Gold Vulnerabilities Demand Immediate Action https://t.co/hObfawlely
New from @Horizon3Attack and @hacks_zach: A PoC for CVE-2024-28987 affecting #SolarWinds Web Help Desk. This vulnerability allows attackers to read all help desk tickets, which often contain sensitive IT procedures. 😬 Visit https://t.co/FkB1UhjfhE for the full deep dive.… https://t.co/ATLeiXg28O