Critical SolarWinds Web Help Desk Flaw (CVE-2024-28925) Bypasses SAML Login
Key Takeaways SolarWinds has released an urgent patch for a critical authentication bypass vulnerability (CVE-2024-28925) in its Web Help Desk software. The flaw, rated 9.8 CVSS, allows attackers to...
Key Takeaways
- SolarWinds has released an urgent patch for a critical authentication bypass vulnerability (CVE-2024-28925) in its Web Help Desk software.
- The flaw, rated 9.8 CVSS, allows attackers to bypass SAML 2.0 single sign-on (SSO), potentially granting unauthorized access to sensitive help desk data.
- The vulnerability specifically impacts Web Help Desk deployments configured with SAML 2.0 authentication.
- The fix is available in Web Help Desk version 2024.2.1, which also includes multiple other security enhancements and fixes.
SolarWinds Patches Critical SAML Bypass in Web Help Desk
SolarWinds has addressed a severe security vulnerability within its Web Help Desk platform that could enable malicious actors to circumvent SAML-based authentication mechanisms. This critical flaw, identified as CVE-2024-28925, poses a significant risk to organizations utilizing the affected software.
Table Of Content
The vulnerability specifically targets SolarWinds Web Help Desk deployments configured for SAML 2.0 single sign-on (SSO). It was resolved in version 2024.2.1, which the vendor released on July 30, 2024. SolarWinds has assigned CVE-2024-28925 a critical CVSS severity score of 9.8, underscoring its potential impact. Security researcher Dhabaleshwar Das is credited with the responsible disclosure of this issue.
SAML, or Security Assertion Markup Language, serves as a cornerstone for enterprise identity management, facilitating secure connections between applications and centralized identity providers such as Microsoft Entra ID, Okta, and Active Directory Federation Services (ADFS). Its primary function is to allow users a single login experience, granting access to various business applications after authenticating with a trusted identity provider.
The Implications of an Authentication Bypass
An authentication bypass within this critical process is profoundly serious, as it directly undermines a fundamental security control. Successful exploitation of CVE-2024-28925 could grant an attacker unauthorized entry to a vulnerable Web Help Desk instance without completing the required SAML login sequence.
The extent of unauthorized access could be considerable. Depending on the compromised account’s context and its associated application permissions, an attacker might expose sensitive data such as help desk tickets, user profiles, internal communications, IT asset inventories, and other operational information managed within the platform. Such information is often highly valuable to attackers seeking to escalate privileges or exfiltrate data.
While SolarWinds has not yet released specific technical details regarding the exploit, affected request paths, or any evidence of active exploitation in the wild, organizations should prioritize addressing this vulnerability immediately. Its critical severity, coupled with the sensitive nature of information typically handled by help desk platforms, makes it an urgent concern.
Help desk portals are frequently accessible to a broad range of users, including employees, contractors, and external clients, making them prime targets for threat actors seeking initial network access or valuable internal data.
Comprehensive Security Updates and Architectural Changes
Although CVE-2024-28925 specifically affects deployments using SAML 2.0 authentication, all administrators are strongly advised to apply the latest update. Web Help Desk version 2024.2.1 includes multiple security fixes beyond the SAML bypass.
Notably, the update also resolves CVE-2024-28299, a high-severity denial-of-service (DoS) flaw with a CVSS score of 8.2. This vulnerability could allow an attacker to crash a Web Help Desk server by exploiting insufficient memory handling. Furthermore, the release incorporates fixes for several third-party pgAdmin vulnerabilities, addressing issues such as remote code execution, command injection, LDAP injection, and TLS certificate validation bypasses.
The latest version of Web Help Desk also introduces significant architectural enhancements, including a redesigned user interface and a new Caddy-based front-end. Security hardening measures have been implemented across the platform, with SolarWinds now exclusively supporting TLS 1.2/1.3, enforcing HTTPS, applying robust security headers, restricting internal services to local access, and removing server version details from HTTP responses.
What You Should Do
- Upgrade Immediately: Administrators must upgrade to SolarWinds Web Help Desk version 2024.2.1 as soon as possible, especially if SAML SSO is enabled.
- Staged Upgrade Path: If upgrading from a version older than 2024.1, first upgrade to 2024.1, confirm normal operation, and then proceed to 2024.2.1.
- Verify SAML Configuration: After the upgrade, thoroughly test SAML authentication with your identity provider to ensure proper functionality.
- Review Access Logs: Scrutinize Web Help Desk access logs for any unusual login activity or unexpected account sessions post-upgrade.
- Migrate Off Servlet Authentication: Be aware that servlet authentication is no longer supported in version 2024.2.1. Customers relying on this method should plan a migration to either SAML 2.0 or HTTP Header authentication, ensuring the new SSO configuration is fully tested and protected by the latest patch.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.