EXPOSURES › CVE-2024-50623
CVE-2024-50623
CRITICAL ⌖ ON CISA KEV · EXPLOITEDCleo's managed file transfer products suffered an unrestricted file upload vulnerability enabling remote code execution with elevated privileges.
Cleo Harmony, VLTrader, and LexiCom products allowed attackers to upload and execute arbitrary files, leading to remote code execution and elevated privileges. This failure is critical for DIB organizations because it directly enables ransomware attacks and violates CMMC/NIST 800-171 controls around secure file transfer and remote access. Organizations must verify patch levels on all managed transfer tools and avoid unpatched vendors.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, indicating severe negligence and avoidable exposure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.