Evidence used
- CISA confirms exploitation in the wild.
- The selected CVSS metric records a network-reachable, unauthenticated path with no user interaction.
- EPSS is 98.61% for the current model date.
BlackTreeCVE IntelligenceCleo · Multiple Products
CISA confirms exploitation in the wild and lists 2025-01-03 as the remediation due date.
CISA confirms exploitation in the wild and lists 2025-01-03 as the remediation due date.
Fix not verifiedCleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.
The upload path does not sufficiently restrict the type, name, location or later execution of attacker-supplied files.
An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may execute code or commands in the affected security context.
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.
The upload path does not sufficiently restrict the type, name, location or later execution of attacker-supplied files.
An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may execute code or commands in the affected security context.
CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.
CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2024-12-13. Known ransomware campaign use is recorded.
No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.
CWE-434: Unrestricted Upload of File with Dangerous Type. The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCommon Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.
Operational remediation based on structured source evidence.
Published 27 Oct 2024 · Last source change 31 Jul 2026, 03:55 UTC · CWE-434 · Unrestricted Upload of File with Dangerous Type
Core structured fields are present and their contributing authorities are shown above.