In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Cleo Harmony | — | Upgrade Cleo Harmony to version 5.8.0.21. | Dec 10, 2024 | Dec 3, 2024 |
| Cleo Lexicom | — | Upgrade Cleo LexiCom to version 5.8.0.21. | Dec 10, 2024 | Dec 3, 2024 |
| Cleo Vltrader | — | Upgrade Cleo VLTrader to version 5.8.0.21. | Dec 10, 2024 | Dec 3, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub