CyberSec.Space Logo
CVEブラウザに戻る

CVE-2024-55956

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2024-12-13
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

Affected Platforms (CPE)

📦
Cleo

Harmony

< 5.8.0.24
📦
Cleo

Lexicom

< 5.8.0.24
📦
Cleo

Vltrader

< 5.8.0.24

References & Advisories

関連する脆弱性情報