Critical severity9.8CISA KEVNVD Advisory· Published Oct 28, 2024· Updated Jul 31, 2026
CVE-2024-50623
CVE-2024-50623
Description
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- Cleo/Harmonydescription
Patches
Vulnerability mechanics
References
2- support.cleo.com/hc/en-us/articles/27140294267799-Cleo-Product-Security-AdvisorynvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
1- Risky Business #774 -- Cleo file transfer appliances under widespread attackRisky Business · Dec 11, 2024