2024-08-22
Hardcoded Credentials in Solar Winds Web Help Desk
Hardcoded credentials in Solar Winds Web Help Desk (WHD) could be exploited to allow a 'remote unauthenticated user to access internal functionality and modify data.' The issue affects WHD versions 12.8.3 HF1 and earlier. Solar Winds has released a hotfix (WHD 12.8.3 HF2) to address the vulnerability. This is the second hotfix for WHD that Solar Winds has released this month. The previous fix addressed a Java Deserialization Remote Code Execution vulnerability.
Editor's Note
Should be obvious that this must be patched quickly. Hardcoded credentials tend to leak shortly after the patch is released (if not before).
Johannes Ullrich
It's 2024, hardcoded credentials need to be ancient history. Make sure your SQA processes screen for them. The update, WHD 12.8.3 HF2, addresses two issues CVE-2024-28987, WHD hard coded credential vulnerability, CVSS score 9.1 and CVE-2024-28986, WHD Java deserialization RCE vulnerability, CVSS score 9.8, previously fixed in WHD 12.8.3 HF1. The hard coded credential flaw can be exploited by unauthenticated users, the Java deserialization flaw requires an authenticated user. Some good news: HF2 includes the fixes from HF1. The hotfix requires installation of three jar files and manually editing the tomcat_server_template.xml file.
Lee Neely
Hardcoded credentials are like catnip to cybercriminals; they are on the prowl and looking to exploit. Given the recent uptick in examples of this sort of exploit and its own recent software security issues, it's a bit surprising that the company didn't fix this before it became a problem. Bottom line: apply the hotfix now.
Curtis Dukes
One more example, as if any were needed, of why a safety first culture, secure by design, is so important to the modern enterprise.
William Hugh Murray
Read more in
Solar Winds: Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)
The Register: SolarWinds left critical hardcoded credentials in its Web Help Desk product
Security Online: SolarWinds Web Help Desk Hit by Critical Vulnerability (CVE-2024-28987)
The Hacker News: Hardcoded Credential Vulnerability Found in SolarWinds Web Help Desk
Bleeping Computer: SolarWinds fixes hardcoded credentials flaw in Web Help Desk