Cleo Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Cleo products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

2

In CISA KEV

2

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

Cleo KEVs Added by Year

Loading...

2 Cleo KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2024-50623

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that...

Confirmed In CISA 13 Dec 2024
CVE-2024-55956

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary...

Confirmed In CISA 17 Dec 2024

Common Vulnerability Classes (CWE)

  • CWE-434 — Unrestricted Upload of File with Dangerous Type 1
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology