logo

U.S. CISA adds Cleo Harmony, VLTrader, and LexiCom flaw to its Known Exploited Vulnerabilities catalog

ID: 6a076788-6df2-5631-bb96-b520522e1119

STIX ID: report--6a076788-6df2-5631-bb96-b520522e1119

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2024-12-14

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA has added CVE-2024-50623 (CVSS 8.8) — an unrestricted file upload/download vulnerability leading to possible remote code execution in Cleo Harmony, VLTrader, and LexiCom — to its Known Exploited Vulnerabilities catalog. Huntress reported active mass exploitation, produced a proof-of-concept that demonstrated arbitrary file writes (including placement in autoruns) and indicated that some patched versions remain exploitable; IOCs and remediation guidance have been published and federal agencies were ordered to remediate by January 3, 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.