EXPOSURES › CVE-2024-55956
CVE-2024-55956
CRITICAL ⌖ ON CISA KEV · EXPLOITEDCleo's managed file transfer products allowed unauthenticated attackers to upload and execute arbitrary commands via an Autorun directory vulnerability.
Cleo Harmony, VLTrader, and LexiCom suffered an unauthenticated file upload flaw that let attackers import and run bash or PowerShell commands by exploiting default Autorun settings. This is a critical, actively exploited vulnerability linked to ransomware that directly violates CMMC/NIST 800-171 controls around unauthenticated access and command execution. DIB organizations must patch immediately, restrict Autorun usage, and audit file upload controls to prevent similar compromises.
Shame score — A critical, actively exploited unauthenticated RCE flaw in managed file transfer products that directly enables ransomware attacks and violates core security controls.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.