CVE-2024-50623
cleo harmomy, cleo vltrader, cleo lexicom
Published 28 Oct 2024 · updated 31 Jul 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 13 Dec 2024, with a remediation deadline of 3 Jan 2025 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
References
- support.cleo.com/hc/en-us/articles/27140294267799-Cleo-Product-Security-Advisory · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-50623 · US Government Resource