Skip to the content.

DIVD-2024-00052 - Remote code execution in Cleo Harmony, VLCTrader and LexiCom

Our reference DIVD-2024-00052
Case lead Alwin Warringa
Researcher(s)
CVE(s)
Products
  • Cleo Harmony
  • Cleo VLTrader
  • Cleo LexiCom
Versions
  • 5.8.0.24 and earlier
Recommendation Upgrade to version 5.8.0.24 or later
Patch status Patch available
Workaround none
Status Open
Last modified 12 Dec 2024 11:35 CET

Summary

Cleo Harmony, VLCTrader and LexiCom versions below 5.8.0.24 are vulnerable for an remote code execution. A successful exploit of this vulnerability could allow an attacker to gain unauthorized access, with potential impacts to the confidentiality, integrity, and availability of the system. This vulnerability is exploitable without authentication.

Recommendations

To remediate CVE-2024-50623 and a pending CVE, upgrade to version 5.8.0.24 or later. You can find a link to the Cleo bulletin at the bottom of this post.

What we are doing

DIVD is currently working to identify parties that are running a vulnerable version of Cleo Harmony, VLCTrader or LexiCom and to notify these parties.

Timeline

Date Description
10 Dec 2024 DIVD starts researching the vulnerability.
10 Dec 2024 DIVD finds fingerprint, preparing to scan.
10 Dec 2024 Case opened and starting first scan.
gantt title DIVD-2024-00052 - Remote code execution in Cleo Harmony, VLCTrader and LexiCom dateFormat YYYY-MM-DD axisFormat %e %b %Y section Case DIVD-2024-00052 - Remote code execution in Cleo Harmony, VLCTrader and LexiCom (still open) :2024-12-10, 2024-12-24 section Events DIVD starts researching the vulnerability. : milestone, 2024-12-10, 0d DIVD finds fingerprint, preparing to scan. : milestone, 2024-12-10, 0d Case opened and starting first scan. : milestone, 2024-12-10, 0d

More information