Article Details

Scrape Timestamp (UTC): 2024-10-16 04:57:57.595

Source: https://thehackernews.com/2024/10/cisa-warns-of-active-exploitation-in.html

Original Article Text

Click to Toggle View

CISA Warns of Active Exploitation in SolarWinds Help Desk Software Vulnerability. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a critical security flaw impacting SolarWinds Web Help Desk (WHD) software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Tracked as CVE-2024-28987 (CVSS score: 9.1), the vulnerability relates to a case of hard-coded credentials that could be abused to gain unauthorized access and make modifications. "SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data," CISA said in an advisory. Details of the flaw were first disclosed by SolarWinds in late August 2024, with cybersecurity firm Horizon3.ai releasing additional technical specifics a month later. The vulnerability "allows unauthenticated attackers to remotely read and modify all help desk ticket details – often containing sensitive information like passwords from reset requests and shared service account credentials," security researcher Zach Hanley said. It's currently not clear how the shortcoming is being exploited in real-world attacks, and by whom. That said, the development comes two months after CISA added another flaw in the same software (CVE-2024-28986, CVSS score: 9.8) to the KEV catalog. In light of active abuse, Federal Civilian Executive Branch (FCEB) agencies are required to apply the latest fixes (version 12.8.3 Hotfix 2 or later) by November 5, 2024, to secure their networks.

Daily Brief Summary

CYBERCRIME // Critical Security Flaw in SolarWinds Help Desk Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reported active exploitation of a critical vulnerability in SolarWinds Web Help Desk software.

The security flaw, labeled as CVE-2024-28987 with a CVSS score of 9.1, involves hardcoded credentials that could allow unauthorized access and data modification.

This vulnerability could enable attackers to read and alter help desk ticket details, potentially exposing sensitive information such as password reset requests and service account credentials.

SolarWinds first reported the flaw in late August 2024, with additional details released by cybersecurity firm Horizon3.ai the following month.

The exact methods of exploitation and the identities of the attackers remain unclear.

Following this report, Federal Civilian Executive Branch (FCEB) agencies are mandated to install specific updates by November 5, 2024, to mitigate the risk.

This vulnerability notification follows shortly after another serious flaw in the same software was cataloged by CISA.