Reference page — cumulative record through Tuesday, October 6, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2024-28987
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H N 9.1 .9330 99.8 YES
AFFECTED
Product Versions Fixed
Web Help Desk 12.8.3 Hotfix 1 and previous versions – —
TIMELINE
Mar 13 Reserved by SolarWinds
Aug 21 Published (CNA: SolarWinds)
Oct 15 Added to CISA KEV, remediation due 2024-11-05
Description
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| March 13, 2024 | Reserved | Reserved by SolarWinds |
| August 21, 2024 | Published | Published (CNA: SolarWinds) |
| October 15, 2024 | KEV ADDED | Added to CISA KEV, remediation due 2024-11-05 |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| SolarWinds | Web Help Desk | — | 12.8.3 Hotfix 1 and previous versions | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-28987 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Tuesday, October 6, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.