CVE-2024-28989: Weak Encryption Key Management in Solar Winds Web Help Desk
NetSpi Technical
MARCH 10, 2025
Last year, the NetSPI red team came across a backup file for Solar Winds Web Help Desk software. This led to an analysis of the software and how it stored encrypted passwords, giving the red team the ability to recover the stored passwords and use them to access other systems. Fixed in: Solar Winds Web Help Desk version 12.8.5
Let's personalize your content