← Back

CVE-2024-55956

Published: Dec 13, 2024Modified: Nov 4, 2025CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

Affected (3)

3 products
Harmony
Lexicom
Vltrader
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Before 5.8.0.24
Before 5.8.0.24
Before 5.8.0.24

Timeline

No history available yet.