Technologyglobal✓ verified · 95%
Cleo Multiple Products Unauthenticated File Upload Vulnerability
- When
- · day precision
- Where
- Global (internet)
- Category
- cyber_exploit · ransomware
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
Sources
- CISA ↗ · first seen 2024-12-17 00:00 UTC
Defaxon links out to the original reporting and never republishes article text.
Correlated events
Computed by the Defaxon correlation engine — linked by shared actors, co-location, and temporal proximity. Scored hypotheses, never causal claims.
No correlated events found in the current window. As more events arrive, connections form automatically.