peter bassill · operator
$ cve CVE-2024-28988 JSON

CVE-2024-28988

9.8
CRITICAL · CVSS 3.1 · EPSS 39.4% (pctl 99)

Patch early

EPSS 39.4% — above the 10% action threshold.

Description

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability was found by the ZDI team after researching a previous vulnerability and providing this report. The ZDI team was able to discover an unauthenticated attack during their research.  We recommend all Web Help Desk customers apply the patch, which is now available.  We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS39.35% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2025-09-01
Last modified2026-06-17

Affected (1)

VendorProduct
solarwindsweb help desk

References

→ the Explorer  ·  watch your stack  ·  NVD