Security Advisory

CVE-2024-55956

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-12-13 00:00:00
Last updated 2025-10-21 22:55:34
Assigner mitre
State PUBLISHED

Description

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.