CISA warns of ransomware gangs exploiting Cleo, CyberPanel bugs
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-50623 | Unauthenticated RCE via Unrestricted File Upload in Cleo Harmony, VLTrader, LexiCom CVE-2024-50623 is an unrestricted file upload and download flaw (CWE-434) in Cleo's managed file transfer products — Harmony, VLTrader, and LexiCom — before version 5.8.0.21. It is reachable over the network with no authentication or user interaction (CVSS 9.8, AV:N/AC:L/PR:N), letting an attacker send crafted requests that upload arbitrary files to the server. The unrestricted upload leads to remote code execution, giving the attacker full control of the host for staging, data theft, or ransomware, while the download capability risks exposure of business files the server moves with trading partners. Any organization running these products is affected, and managed file transfer servers are typically internet-facing and handle sensitive B2B data. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2024-12-13 with ransomware use noted, EPSS assigns a 98.6% probability of exploitation within 30 days, and the Clop ransomware gang has claimed dozens of breaches (some disputed), including a confirmed breach at WK Kellogg. Do: Upgrade Harmony, VLTrader, and LexiCom to 5.8.0.21 or later per vendor instructions; if upgrading is not possible, apply vendor mitigations or discontinue use of the product, as CISA's KEV entry requires. Prioritize internet-exposed instances, hunt for indicators of compromise (unexpected file writes and execution on the transfer host, new accounts, suspicious outbound connections), and restrict the service to trusted partner networks. Given known ransomware use by Clop, any suspected compromise should trigger checks for lateral movement and staged exfiltration of transferred files. | 9.8 | 99% | KEV ransomware |
| moderate≈1,000–3,000 internet-exposed Cleo servers (tens of thousands of enterprise deployments) | |
| CVE-2024-51378 | Unauthenticated Command Injection in CyberPanel CyberPanel versions through 2.3.6, and 2.3.7 before commit 1c0c6cb, contain an OS command injection flaw (CWE-78) in the getresetstatus functions of dns/views.py and ftp/views.py. Because the security middleware (secMiddleware) only enforces authentication on POST requests, a remote unauthenticated attacker can send a GET request to /dns/getresetstatus or /ftp/getresetstatus and inject shell metacharacters into the statusfile parameter, executing arbitrary commands as the service. Successful exploitation yields full command execution on the hosting server with high impact to confidentiality, integrity, and availability (CVSS 9.8). Any internet-exposed CyberPanel instance, commonly used by web hosts to manage DNS and FTP services, is affected. The flaw was mass-exploited in the wild in October 2024 by the PSAUX ransomware group against roughly 22,000 CyberPanel instances, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-12-04 with ransomware use confirmed. Do: Upgrade CyberPanel to a build that includes commit 1c0c6cb or later (2.3.7 alone is unpatched), per vendor instructions, or discontinue/restrict use of the product per CISA's KEV required action. Check web access logs for GET requests to /dns/getresetstatus and /ftp/getresetstatus from unauthenticated sources and review servers for PSAUX ransomware indicators. If immediate patching is not possible, restrict panel endpoints to trusted networks and block unauthenticated GET access to the affected routes. | 9.8 | 95% | KEV ransomware PoC ×2 |
| large≈20,000–30,000 internet-exposed CyberPanel instances (PSAUX attacks hit ~22,000 instances) |
Full article649 words · extracted from therecord.media · click to collapse
Two recently disclosed vulnerabilities are being used by ransomware gangs to attack organizations across the U.S., according to the nation’s top cybersecurity agency. Over the last two weeks, the Cybersecurity and Infrastructure Security Agency (CISA) has taken the rare step of confirming that ransomware actors are exploiting specific bugs, ordering government agencies to urgently patch the two vulnerabilities as soon as possible. On Friday, CISA said federal civilian agencies have until January 3 to patch CVE-2024-50623 — a vulnerability that has caused alarm among cybersecurity experts this week because of its impact on a widely used file-sharing product from software company Cleo. The bug affects three file-sharing products: Cleo Harmony, VLTrader and LexiCom. Cleo Harmony and VLTrader are used to send large amounts of data and are built for more enterprise-level file sharing needs, while LexiCom is a lighter solution oftentimes used by smaller organizations to send files. Cybersecurity companies have since reported dozens of customers being breached through the vulnerability, which was originally patched by Cleo in October. Researchers discovered last week that the patch was ineffective and hackers — some of whom are allegedly part of the Termite ransomware gang — have been exploiting it since December 7. Researchers discovered a new family of malware being used in attacks, which have mostly affected victims in the consumer products, shipping and retail supply industries, according to several incident responders. The addition of the Cleo vulnerability comes nine days after CISA added another bug to its catalog of exploited vulnerabilities that it said ransomware gangs were exploiting. CISA ordered federal civilian agencies to patch CVE-2024-51378, which affects a product from software company CyberPanel, by Christmas Day. CyberPanel products allow people to manage websites, domains, email, and other hosting features on a Linux server. Organizations typically use CyberPanel for web hosting management, email management, database management and WordPress hosting, according to researchers. Malicious actors were able to infect several CyberPanel instances, experts warned, after a technical write-up about the vulnerability was released in late October. Scott Caveza, staff research engineer at Tenable, said a GitHub repo indicates that at least three ransomware variants have been found on infected CyberPanel instances: a variant of the Babuk ransomware, a Cerber ransomware variant and the PSAUX ransomware. BleepingComputer reported in October that more than 22,000 CyberPanel instances were targeted in a PSAUX ransomware attack, shutting down nearly all of them. Mike Walters, co-founder of cybersecurity firm Action1, told Recorded Future that PSAUX ransomware actors have been targeting web servers through vulnerabilities like the one affecting CyberPanel since emerging in June, and urged CyberPanel users to update to the latest version available on GitHub as soon as possible. CISA said it would begin adding information about whether ransomware gangs are exploiting a vulnerability public through its catalog in October 2023.Previously, it had shared the data with organizations through its Ransomware Vulnerability Warning Pilot Program (RVWP). The addition was intended to serve as another reason for federal civilian agencies and other organizations to be proactive about patching vulnerabilities. Nonetheless, the information has seldom been provided. On the forms describing vulnerabilities, the “Known To Be Used in Ransomware Campaigns?” tab has been left an “unknown” outside of a few rare cases. The addition of two bugs acknowledged as exploited by ransomware actors was notable to cybersecurity experts. “While it’s not often that CISA KEV vulnerabilities are flagged as being attributed to ransomware groups, in this case, there is sufficient evidence to suggest that multiple opportunistic attackers targeted this vulnerability with multiple ransomware strains,” Caveza said of the CyberPanel bug.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-ransomware-cleo-cyberpanel-bugs