CVE-2024-50623: Cleo Multiple Products Unrestricted File Upload Vulnerability
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.
Other sources
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cleo Harmonyto a version that resolves this vulnerability.Fixed in 5.8.0.21 - Upgrade
Upgrade
VLTraderto a version that resolves this vulnerability.Fixed in 5.8.0.21 - Upgrade
Upgrade
LexiComto a version that resolves this vulnerability.Fixed in 5.8.0.21 - Compensating control
If updating to 5.8.0.21 (or later) is not possible, discontinue use of Cleo Harmony, VLTrader, and/or LexiCom until the unrestricted file upload/download vulnerability is mitigated.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50623?
CVE-2024-50623 is considered a critical vulnerability due to the potential for remote code execution with elevated privileges.
How do I fix CVE-2024-50623?
To fix CVE-2024-50623, upgrade to Cleo Harmony version 5.8.0.21, VLTrader version 5.8.0.21, or LexiCom version 5.8.0.21.
What products are affected by CVE-2024-50623?
CVE-2024-50623 affects Cleo Harmony, VLTrader, and LexiCom prior to versions 5.8.0.21.
Can CVE-2024-50623 lead to data theft?
Yes, CVE-2024-50623 can potentially lead to data theft due to its unrestricted file upload and download vulnerability.
What are the implications of exploiting CVE-2024-50623?
Exploitation of CVE-2024-50623 can allow an attacker to execute arbitrary code remotely with elevated privileges.