CVE-2024-55956

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Dec 13, 2024
Updated: Dec 20, 2024
CWE ID 77
CWE ID 276

Summary

CVE-2024-55956 is a vulnerability affecting Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24. An unauthenticated attacker can exploit the default settings of the Autorun directory to import and execute arbitrary Bash or PowerShell commands on the host system, posing a significant security risk. This issue allows an attacker to gain unauthorized access and potentially cause damage to the affected system. It is important for users to update their software to the latest versions to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • VLTrader
  • Cleo LexiCom
  • Harmony

Affected Vendors

  • CLEO COMMUNICATIONS INC
  • Nordson Corporation