Loading
An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filename can include path-traversal characters, allowing the file to be written to an arbitrary location on disk.
Use CWE-22, Cleo vendor hub and Lexicom product page to widen CVE-2021-33576 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-55956, CVE-2024-50623 and CVE-2021-33577 for nearby disclosures in the same product family.