CVE-2024-50623
CVSS 3.1 Score 9.8 of 10 (CRITICAL)
Attack Complexity
LOW
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
Scope
UNCHANGED
Privileges Required
NONE
Summary
CVE-2024-50623 is a critical vulnerability affecting Cleo Harmony versions prior to 5.8.0.21, VLTrader versions prior to 5.8.0.21, and LexiCom versions prior to 5.8.0.21. This issue allows for an unrestricted file upload and download, enabling attackers to potentially execute remote code on affected systems. Successful exploitation could lead to significant security risks, including data breaches and unauthorized system access. Users are strongly advised to update their software to the latest versions to mitigate this vulnerability.
Details
- Published: formatDate( 2024-10-28T00:15:03.657Z )
- Updated: formatDate( 2024-12-23T06:15:06.357Z )
- CWE ID: CWE-434
Affected Products
Cleo LexiCom,Cleo VLTrader,Cleo Harmony
Affected Vendors
CLEO COMMUNICATIONS INC