CVE-2024-55956
CVSS 3.1 Score 9.8 of 10 (CRITICAL)
Attack Complexity
LOW
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
Scope
UNCHANGED
Privileges Required
NONE
Summary
CVE-2024-55956 is a vulnerability affecting Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24. An unauthenticated attacker can exploit the default settings of the Autorun directory to import and execute arbitrary Bash or PowerShell commands on the host system, posing a significant security risk. This issue allows an attacker to gain unauthorized access and potentially cause damage to the affected system. It is important for users to update their software to the latest versions to mitigate this vulnerability.
Details
- Published: formatDate( 2024-12-13T21:15:13.767Z )
- Updated: formatDate( 2024-12-20T15:21:39.287Z )
- CWE ID: CWE-77,CWE-276
Affected Products
VLTrader,Cleo LexiCom,Harmony
Affected Vendors
CLEO COMMUNICATIONS INC,Nordson Corporation