CVE CVE

CVE-2024-55956

CISA Known Exploited Vulnerability (KEV)

Cleo Multiple Products Unauthenticated File Upload Vulnerability

December 17, 2024

January 7, 2025

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

Weakness Enumeration

CWE-ID CWE Name

CWE-77
Improper Neutralization of Special Elements used in a Command (‘Command Injection’)

CWE-276
Incorrect Default Permissions

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
9.8
Severity:

CRITICAL

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2

Not defined