Arbitrary file upload in Cleo products - CVE-2024-55956
Published: December 10, 2024 / Updated: January 15, 2025
Vulnerability identifier: #VU101393
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-55956
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload. A remote attacker can upload a malicious file and execute it on the server.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Cleo LexiCom
Cleo VLTrader
Cleo Harmony
Cleo VLTrader
Cleo Harmony
How to mitigate CVE-2024-55956
Install updates from vendor's website.
Cleo LexiCom - update to 5.8.0.24
Cleo VLTrader - update to 5.8.0.24
Cleo Harmony - update to 5.8.0.24
Cleo VLTrader - update to 5.8.0.24
Cleo Harmony - update to 5.8.0.24