CVE-2024-50623

CVSS 3.1 Score 9.8 of 10 (CRITICAL)

Attack Complexity
LOW
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
Scope
UNCHANGED
Privileges Required
NONE
Summary

CVE-2024-50623 is a critical vulnerability affecting Cleo Harmony versions prior to 5.8.0.21, VLTrader versions prior to 5.8.0.21, and LexiCom versions prior to 5.8.0.21. This issue allows for an unrestricted file upload and download, enabling attackers to potentially execute remote code on affected systems. Successful exploitation could lead to significant security risks, including data breaches and unauthorized system access. Users are strongly advised to update their software to the latest versions to mitigate this vulnerability.

Details
  • Published: formatDate( 2024-10-28T00:15:03.657Z )
  • Updated: formatDate( 2024-12-23T06:15:06.357Z )
  • CWE ID: CWE-434
Affected Products

Cleo LexiCom,Cleo VLTrader,Cleo Harmony

Affected Vendors

CLEO COMMUNICATIONS INC

Advisories, Assessments, and Mitigations