CVE-2024-28986 is a critical Java Deserialization Remote Code Execution vulnerability affecting SolarWinds Web Help Desk, allowing attackers to execute commands on the host machine. It carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and complete compromise potential (C:H/I:H/A:H). This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered significant community attention with numerous discussions and public exploit templates available. SolarWinds has released a patch, which is strongly recommended for all customers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 12.8.2CPE matchmatch criteria | cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:* | ||
12.8.3CPE matchmatch criteria | cpe:2.3:a:solarwinds:web_help_desk:12.8.3:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.