CVE-2024-55956
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 13, 2024
Updated: Dec 20, 2024
CWE ID 77
CWE ID 276
Summary
CVE-2024-55956 is a vulnerability affecting Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24. An unauthenticated attacker can exploit the default settings of the Autorun directory to import and execute arbitrary Bash or PowerShell commands on the host system, posing a significant security risk. This issue allows an attacker to gain unauthorized access and potentially cause damage to the affected system. It is important for users to update their software to the latest versions to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- VLTrader
- Cleo LexiCom
- Harmony
Affected Vendors
- CLEO COMMUNICATIONS INC
- Nordson Corporation