PT-2024-5811 · Solarwinds · Solarwinds Web Help Desk

Published

2024-08-09

·

Updated

2025-09-27

·

CVE-2024-28986

CVSS v2.0
10
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C

**Name of the Vulnerable Software and Affected Versions**

SolarWinds Web Help Desk versions prior to 12.8.3 Hotfix 2

**Description**

SolarWinds Web Help Desk is susceptible to a Java deserialization remote code execution issue. Exploitation of this issue could allow an attacker to execute arbitrary commands on the host machine. The vulnerability is reported as being actively exploited. While initially reported as unauthenticated, SolarWinds has been unable to reproduce it without authentication after thorough testing. There have been reports of approximately 812 exposed instances globally, with 527 located in the United States. The **API endpoints** are not explicitly mentioned in the provided data. The vulnerability stems from improper handling of deserialization of untrusted data.

**Recommendations**

Update SolarWinds Web Help Desk to version 12.8.3 Hotfix 2 or later.

Audit all admin accounts on SolarWinds Web Help Desk.

Ensure backups of critical data are up-to-date.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2024-06556
CVE-2024-28986

Affected Products

Solarwinds Web Help Desk