CVE-2024-55956
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
13/12/2024
Last modified:
04/11/2025
Description
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cleo:harmony:*:*:*:*:*:*:*:* | 5.8.0.24 (excluding) | |
| cpe:2.3:a:cleo:lexicom:*:*:*:*:*:*:*:* | 5.8.0.24 (excluding) | |
| cpe:2.3:a:cleo:vltrader:*:*:*:*:*:*:*:* | 5.8.0.24 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Advisory-CVE-Pending
- https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Update
- https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-55956



