FAIL › dossier
Cleo
VENDOR· dossier confidence 50%
Cleo, a provider of managed file transfer solutions, has experienced multiple critical remote code execution vulnerabilities in late 2024, indicating significant security weaknesses. These incidents necessitate immediate review of Cleo's security practices and potential impact on data security within the DIB. Remediation efforts should focus on improving vulnerability management and secure coding practices.
PROFILE
CategorySoftwareWhat they doCleo provides managed file transfer (MFT) and business integration solutions. Their products facilitate secure data exchange between organizations and applications.
SECURITY POSTURE
Cleo has demonstrated a critical vulnerability posture, with multiple critical remote code execution vulnerabilities discovered within a short timeframe. These vulnerabilities highlight a potential lack of robust security controls and timely patching processes.
Notable failures
- CVE-2024-55956 (RCE) - Autorun directory vulnerability
- CVE-2024-50623 (RCE) - Unrestricted file upload
- CVE-2024-50623 (RCE) - Cleo Harmony, VLTrader, LexiCom versions before 5.8.0.21
Patterns: Unrestricted file upload vulnerabilities; Remote code execution (RCE) vulnerabilities; Lack of timely patching
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-12-17 | CVE-2024-55956 | critical | Cleo's managed file transfer products allowed unauthenticated attackers to upload and execute arbitrary commands via an Autorun directory vulnerability. |
| 2024-12-13 | CVE-2024-50623 | critical | Cleo's managed file transfer products suffered an unrestricted file upload vulnerability enabling remote code execution with elevated privileges. |
| 2024-12-13 | CVE-2024-55956 | critical | CVE-2024-55956: In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5. |
| 2024-10-28 | CVE-2024-50623 | critical | CVE-2024-50623: In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5. |
Open questions: What is the root cause of the repeated RCE vulnerabilities? · What remediation steps have been taken to address the identified vulnerabilities? · What is Cleo's vulnerability disclosure process?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-04 04:06:23.218426+00:00