CVE-2024-50623

cleo harmomy, cleo vltrader, cleo lexicom

Published 28 Oct 2024 · updated 31 Jul 2026 · Analyzed

9.8 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 13 Dec 2024, with a remediation deadline of 3 Jan 2025 for US federal agencies. It has been used in ransomware campaigns.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

References