CVE-2024-55956
Cleo Multiple Products Unauthenticated File Upload Vulnerability
⚠ KEVEPSS 93.8%
描述
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
如何修補 CVE-2024-55956
OSV 沒有提供套件對應 — 請參考下方連結尋找廠商提供的建議。
CVE-2024-55956 正在被利用嗎?
是 — CVE-2024-55956 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(0)
OSV 沒有提供套件對應。