Skip to content

Commit 7279c92

Browse files
20250108002 (#1150)
* 20250108002 * Update and rename 20250108002 Changed Title and updated Overview to reflect this is newly developed information, and not re-advising on the same CVE. Included link to original advisory in Overview. --------- Co-authored-by: JadonWill <[email protected]>
1 parent c7cb31a commit 7279c92

File tree

1 file changed

+25
-0
lines changed

1 file changed

+25
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
# SolarWinds Web Help Desk Vulnerability Scanner and Exploiter - 20250108002
2+
3+
## Overview
4+
5+
Since publishing [Advisory 20241001001](https://soc.cyber.wa.gov.au/advisories/20241001001-SolarWinds-Critical-Vulnerability/), the WA SOC has been notified of a new Python-based exploit and scanner for SolarWinds Web Help Desk. This tool tests if the target is vulnerable to CVE-2024-28987 by attempting to access the /OrionTickets endpoint, and if so, to then retrieve and save all helpdesk tickets from the vulnerable endpoint.
6+
7+
## What is vulnerable?
8+
9+
| Product(s) Affected | Version(s) | CVE | CVSS | Severity |
10+
| ------------------- | ---------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ------------ | -------------------------------------------------------------- |
11+
| SolarWinds Web Help Desk | Version WHD 12.8.3 HF1 and earlier | [CVE-2024-28987](https://nvd.nist.gov/vuln/detail/CVE-2024-28987) | 9.1 | **Critical** |
12+
13+
## What has been observed?
14+
15+
There is no evidence of exploitation affecting Western Australian Government networks at the time of publishing.
16+
17+
## Recommendation
18+
19+
The WA SOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframe of *48 hours...* (refer [Patch Management](../guidelines/patch-management.md)):
20+
21+
- SolarWinds: <https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28987>
22+
23+
## Additional References
24+
25+
- Dark Web Informer: <https://darkwebinformer.com/cve-2024-28987-scanner-exploiter-solarwinds-web-help-desk/>

0 commit comments

Comments
 (0)