Security
Loading…

CVE-2024-55956

CRITICALCVSS 9.8Known Exploited
Description

Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

Timeline
Published:December 13th, 2024 9:15 PM
Last modified:August 5th, 2026 5:16 AM
Added to KEV:December 17th, 2024
CVSS Scoring

CVSS v3: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

cleo

Products

harmonylexicomvltrader
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute