Skip to content
COOEY

EXPOSURES › CVE-2024-55956

CVE-2024-55956

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-12-17 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-55956 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Cleo's managed file transfer products allowed unauthenticated attackers to upload and execute arbitrary commands via an Autorun directory vulnerability.

Cleo Harmony, VLTrader, and LexiCom suffered an unauthenticated file upload flaw that let attackers import and run bash or PowerShell commands by exploiting default Autorun settings. This is a critical, actively exploited vulnerability linked to ransomware that directly violates CMMC/NIST 800-171 controls around unauthenticated access and command execution. DIB organizations must patch immediately, restrict Autorun usage, and audit file upload controls to prevent similar compromises.

Shame score — A critical, actively exploited unauthenticated RCE flaw in managed file transfer products that directly enables ransomware attacks and violates core security controls.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.