CVE-2024-55956
Cleo · Published December 13, 2024
9.8
CVSS v3.1
CRITICALCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
Affected Products
- Harmony < 5.8.0.24
- Lexicom < 5.8.0.24
- Vltrader < 5.8.0.24
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H