Security
Loading…

CVE-2024-50623

CRITICALCVSS 9.8Known Exploited
Description

Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.

Timeline
Published:October 28th, 2024 12:15 AM
Last modified:July 31st, 2026 4:16 AM
Added to KEV:December 13th, 2024
CVSS Scoring

CVSS v3: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

cleo

Products

harmonylexicomvltrader
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute