Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2024-28988

Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-502 Deserialización de datos no confiables
Fecha de publicación:
01/09/2025
Última modificación:
14/11/2025

Descripción

*** Pendiente de traducción *** SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability was found by the ZDI team after researching a previous vulnerability and providing this report. The ZDI team was able to discover an unauthenticated attack during their research. <br /> <br /> <br /> <br /> <br /> <br /> We recommend all Web Help Desk customers apply the patch, which is now available. <br /> <br /> <br /> <br /> <br /> <br /> We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:* 12.8.2 (incluyendo)
cpe:2.3:a:solarwinds:web_help_desk:12.8.3:-:*:*:*:*:*:*
cpe:2.3:a:solarwinds:web_help_desk:12.8.3:hotfix1:*:*:*:*:*:*
cpe:2.3:a:solarwinds:web_help_desk:12.8.3:hotfix2:*:*:*:*:*:*