THREAT OPS › CVEs › CVE-2024-50623
CVE-2024-50623 — Cleo Multiple Products Unrestricted File Upload Vulnerability
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.
Vulnerability details
- Affected productsMultiple Products
- KEV remediation due2025-01-03
Related reporting
- [NVD] CVE-2024-50623 (CRITICAL 9.8) — In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.nvd
- You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)watchtowr