CVE-2024-50623

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 28, 2024
Updated: Dec 23, 2024
CWE ID 434

Summary

CVE-2024-50623 is a critical vulnerability affecting Cleo Harmony versions prior to 5.8.0.21, VLTrader versions prior to 5.8.0.21, and LexiCom versions prior to 5.8.0.21. This issue allows for an unrestricted file upload and download, enabling attackers to potentially execute remote code on affected systems. Successful exploitation could lead to significant security risks, including data breaches and unauthorized system access. Users are strongly advised to update their software to the latest versions to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cleo LexiCom
  • Cleo VLTrader
  • Cleo Harmony

Affected Vendors

  • CLEO COMMUNICATIONS INC