CVE-2024-55956
Last modified
CVE-2024-55956 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.. CISA has confirmed active exploitation in the wild. EPSS estimates a 93.80% chance of exploitation in the next 30 days.
Description
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cleo | Harmony | < 5.8.0.24 |
| Cleo | Lexicom | < 5.8.0.24 |
| Cleo | Vltrader | < 5.8.0.24 |
References
- https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wildExploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-55956US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-55956?
How severe is CVE-2024-55956?
How do I fix CVE-2024-55956?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-55950Tabby (formerly Terminus) is a highly configurable terminal …8.6
- CVE-2024-55951Metabase is an open-source data analytics platform. For new …4.8
- CVE-2024-55952DataEase is an open source business analytics tool. Authenti…8.8
- CVE-2024-55953DataEase is an open source business analytics tool. Authenti…8.1
- CVE-2024-55954OpenObserve is a cloud-native observability platform. A vuln…8.7
- CVE-2024-55955An incorrect permissions assignment vulnerability in Trend M…7.3
- CVE-2024-55957In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Ther…7.8
- CVE-2024-55958Northern.tech CFEngine Enterprise Mission Portal 3.24.0, 3.2…4.8
- CVE-2024-55959Northern.tech Mender Client 4.x before 4.0.5 has Insecure Pe…9.1
- CVE-2024-5596The ARMember Premium plugin for WordPress is vulnerable to C…6.3
- CVE-2024-55963An issue was discovered in Appsmith before 1.51. A user on A…6.5
- CVE-2024-55964An issue was discovered in Appsmith before 1.52. An incorrec…9.8
Are you affected by CVE-2024-55956?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
