📦 Lexicom

by Cleo

🔍 What is Lexicom?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-55956

CRITICAL CVSS 9.8 Dec 13, 2024

This vulnerability allows unauthenticated attackers to execute arbitrary Bash or PowerShell commands on affected Cleo systems by exploiting the default Autorun directory settings. It affects Cleo Harm...

CVE-2024-50623

CRITICAL CVSS 9.8 Oct 28, 2024

This vulnerability allows attackers to upload and download files without restrictions in Cleo's Harmony, VLTrader, and LexiCom products, potentially leading to remote code execution (RCE). It affects ...

CVE-2021-33576

CRITICAL CVSS 9.8 Jun 18, 2021

CVE-2021-33576 is a path traversal vulnerability in Cleo LexiCom AS2 file transfer software. Attackers can manipulate filenames in AS2 messages to write files to arbitrary locations on the server's fi...