Junglewise Threat Intelligence

CVE-2024-50623: Cleo Multiple Products Unrestricted File Upload Vulnerability

CVE-2024-50623 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-12-13

Technologies: Apple Multiple Products. Vendors: Apple.

Executive brief

Cleo Harmony, VLTrader, and LexiCom managed file transfer products contain an unrestricted file upload and download vulnerability. This flaw allows unauthenticated remote attackers to execute arbitrary code with elevated privileges on the affected system.

Affected products

  • Cleo Harmony before 5.8.0.21
  • Cleo VLTrader before 5.8.0.21
  • Cleo LexiCom before 5.8.0.21

Timeline

  • 2024-10-27: disclosed: Initial CVE publication
  • 2024-12-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-12-13: advisory: Vendor advisory updated/published

Related threats