CVE-2024-50623

CRITICAL KEV RANSOMWARE NUCLEI

Cleo Harmony < 5.8.0.21 - Unrestricted File Upload

Title source: rule

Description

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

Exploits (5)

github WORKING POC 40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/CVE-2024-50623.py
nomisec WORKING POC 25 stars
by watchtowrlabs · infoleak
https://github.com/watchtowrlabs/CVE-2024-50623
nomisec WORKING POC 8 stars
by verylazytech · remote
https://github.com/verylazytech/CVE-2024-50623
nomisec WORKING POC 5 stars
by iSee857 · remote
https://github.com/iSee857/Cleo-CVE-2024-50623-PoC
nomisec WORKING POC
by congdong007 · infoleak
https://github.com/congdong007/CVE-2024-50623-poc

Nuclei Templates (1)

Cleo Harmony < 5.8.0.21 - Arbitary File Read
HIGHVERIFIEDby DhiyaneshDK
Shodan: Server: Cleo

Scores

CVSS v3 9.8
EPSS 0.9401
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2024-12-13
VulnCheck KEV 2024-12-09
InTheWild.io 2024-12-13
ENISA EUVD EUVD-2024-45217
Ransomware Use Confirmed
CWE
CWE-434
Status published
Products (3)
cleo/harmony < 5.8.0.21
cleo/lexicom < 5.8.0.21
cleo/vltrader < 5.8.0.21
Published Oct 28, 2024
KEV Added Dec 13, 2024
Tracked Since Feb 18, 2026