U.S. CISA adds Cleo Harmony, VLTrader, and LexiCom flaw to its Known Exploited Vulnerabilities catalog
ID: 6a076788-6df2-5631-bb96-b520522e1119
STIX ID: report--6a076788-6df2-5631-bb96-b520522e1119
Feed Name: Security Affairs
CISA has added CVE-2024-50623 (CVSS 8.8) — an unrestricted file upload/download vulnerability leading to possible remote code execution in Cleo Harmony, VLTrader, and LexiCom — to its Known Exploited Vulnerabilities catalog. Huntress reported active mass exploitation, produced a proof-of-concept that demonstrated arbitrary file writes (including placement in autoruns) and indicated that some patched versions remain exploitable; IOCs and remediation guidance have been published and federal agencies were ordered to remediate by January 3, 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
