KEVIntel
9.8
CVSS
Critical

CVE-2024-50623

PUBLISHED

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that...

Exploited in the wild Used in malware PoC available Remote Low complexity No user interaction
Vendor
Cleo
Product
["Harmony", "VLTrader", "LexiCom"]
Published
Oct 27, 2024
EPSS

Description

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

cisa malware ransomware nuclei_scanner nessus_scanner

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2024-12-13 00:00:00 UTC · Source

Used in malware

Recorded 2024-12-13 00:00:00 UTC · Source

Proof of concept available

Recorded 2024-12-11 14:19:55 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Dec 13, 2024

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

iSee857/Cleo-CVE-2024-50623-PoC

github · Created 2024-12-31 07:43:48 UTC · 4 stars

Cleo 远程代码执行漏洞批量检测脚本(CVE-2024-50623)

verylazytech/CVE-2024-50623

github · Created 2024-12-23 08:52:23 UTC · 6 stars

CVE-2024-50623 POC - Cleo Unrestricted file upload and download

watchtowrlabs/CVE-2024-50623

github · Created 2024-12-11 14:19:55 UTC · 22 stars

Cleo Unrestricted file upload and download PoC (CVE-2024-50623)

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Nessus

  • Detected by Nuclei