CVE-2024-28989: Weak Encryption Key Management in Solar Winds Web Help Desk
netspi.com | vulnerability | CVE-2024-28989 | #encryption | #solarwinds | #aes-gcm | #web-help-desk | #cve-2024-28989 | #password-recovery
Summary
CVE-2024-28989: SolarWinds Web Help Desk uses predictable AES-GCM keys—some static, some from a restricted keyspace—so an attacker with a backup file can recover stored passwords. Fixed in 12.8.5.
- CVE
- CVE-2024-28989
- Published
- Collected
Skip to content