CVE-2024-55956

KEV
🔴 Łataj teraz

W Cleo Harmony, VLTrader i LexiCom umożliwia to zdalne wykonanie dowolnych poleceń na systemie.

CVSS
9.8
EPSS
93.8%
Exploit
weaponized
Vendor
cleo
Opis źródłowy (NVD)

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Tak
FIRST EPSS (prawdopodobieństwo exploita)93.8%
Opublikowano (NVD)2024-12-13 21:15:13 UTC
Ostatnia modyfikacja (NVD)2026-08-05 05:16:42 UTC
Referencje