ZeroHour
Recorded Futurepublished ()ingested Sam Langrock

Cleo MFT Vulnerability CVE-2024

criticalVulnerability exploited in the wildimportance 60CVE-2024-50623CVE-2024-55956

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-50623
Unauthenticated RCE via Unrestricted File Upload in Cleo Harmony, VLTrader, LexiCom

CVE-2024-50623 is an unrestricted file upload and download flaw (CWE-434) in Cleo's managed file transfer products — Harmony, VLTrader, and LexiCom — before version 5.8.0.21. It is reachable over the network with no authentication or user interaction (CVSS 9.8, AV:N/AC:L/PR:N), letting an attacker send crafted requests that upload arbitrary files to the server. The unrestricted upload leads to remote code execution, giving the attacker full control of the host for staging, data theft, or ransomware, while the download capability risks exposure of business files the server moves with trading partners. Any organization running these products is affected, and managed file transfer servers are typically internet-facing and handle sensitive B2B data. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2024-12-13 with ransomware use noted, EPSS assigns a 98.6% probability of exploitation within 30 days, and the Clop ransomware gang has claimed dozens of breaches (some disputed), including a confirmed breach at WK Kellogg.

Do: Upgrade Harmony, VLTrader, and LexiCom to 5.8.0.21 or later per vendor instructions; if upgrading is not possible, apply vendor mitigations or discontinue use of the product, as CISA's KEV entry requires. Prioritize internet-exposed instances, hunt for indicators of compromise (unexpected file writes and execution on the transfer host, new accounts, suspicious outbound connections), and restrict the service to trusted partner networks. Given known ransomware use by Clop, any suspected compromise should trigger checks for lateral movement and staged exfiltration of transferred files.

9.899% KEV ransomware
  • Cleo Harmony before 5.8.0.21
  • Cleo VLTrader before 5.8.0.21
  • Cleo LexiCom before 5.8.0.21
moderate≈1,000–3,000 internet-exposed Cleo servers (tens of thousands of enterprise deployments)
CVE-2024-55956
Unauthenticated File Upload RCE in Cleo Harmony, VLTrader, and LexiCom

CVE-2024-55956 is an unauthenticated command-execution flaw (CWE-77) in Cleo's managed file transfer products: by default the Autorun directory automatically imports and runs files, so an unauthenticated attacker can import Bash or PowerShell commands that execute on the host. It is triggered over the network with no authentication and no user interaction (CVSS 3.1 score 9.8), by sending crafted import requests to a vulnerable Cleo server. Successful exploitation yields arbitrary command execution on the server, enabling data theft, lateral movement, and ransomware deployment. Any organization running Cleo Harmony, VLTrader, or LexiCom before 5.8.0.24 is affected — typically enterprises using these servers for EDI and partner file exchange. The flaw is actively exploited in the wild: it was added to CISA KEV on 2024-12-17 with known ransomware use (widely attributed to Cl0p), EPSS is 94% (top percentile), and confirmed downstream breaches such as WK Kellogg's have been tied to it.

Do: Upgrade all Cleo Harmony, VLTrader, and LexiCom instances to 5.8.0.24 or later immediately, per the CISA KEV required action to apply vendor mitigations or discontinue use. If patching is delayed, restrict or remove internet exposure of the server. Because exploitation is confirmed and ransomware-linked, inspect the Autorun directory for unexpected imported files, review application logs for executed commands, and hunt for signs of data exfiltration or staging.

9.894% KEV ransomware PoC
  • cleo Harmony before 5.8.0.24
  • cleo VLTrader before 5.8.0.24
  • cleo LexiCom before 5.8.0.24
largetens of thousands of installations (Cleo cites 100,000+ business customers; public internet scans showed roughly 1,000–2,000 exposed instances)
Full article463 words · extracted from recordedfuture.com · click to collapse

What is CVE-2024-50623

CVE-2024-50623 is a critical unrestricted file upload and download vulnerability that could lead to remote code execution (RCE).

What are the affected products?

The vulnerability affects Cleo's managed file transfer (MFT) products Harmony, VLTrader, and LexiCom before version 5.8.0.21.

  • Cleo Harmony 5.8
  • Cleo LexiCom 5.5.0.0
  • Cleo LexiCom 5.6
  • Cleo LexiCom 5.6.1
  • Cleo LexiCom 5.6.2
  • Cleo LexiCom 5.7
  • Cleo LexiCom 5.8
  • Cleo VLTrader 5.8

Description

On December 13, 2024, Recorded Future’s Insikt Group published a TTP Instance detailing cybersecurity firm watchTowr Labs’ analysis of an alleged proof-of-concept (PoC) exploit for CVE-2024-50623.

CVE-2024-50623 stems from insufficient input validation, improper path sanitization, and weak license verification logic within the /Synchronization endpoint of the affected Cleo software. The /Synchronization endpoint facilitates file synchronization, transfer, and command-based file operations (read, write, update, delete) between Cleo cluster nodes.

Login page for dashboard management on an exposed Cleo instance

Insikt Group also published a TTP Instance on December 13, 2024 discussing CVE-2024-55956, a related command injection vulnerability that allows unauthenticated users to run unauthorized commands on a system using Cleo’s Autorun directory. According to cybersecurity firm Huntress, Cleo's patch in version 5.8.0.21 failed to fully address CVE-2024-50623; Cleo released version 5.8.0.24 to fix the then-zero day vulnerability, which was later assigned CVE-2024-55956.

Both CVE-2024-50623 and the related CVE-2024-55956 are listed in the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) database. Cybersecurity firm GreyNoise also observed malicious hosts looking to exploit the vulnerabilities.

On December 26, 2024, Insikt Group published a TTP Instance detailing the CL0P ransomware group exploiting both CVE-2024-50623 and CVE-2024-55956. At the time of writing, there were 1,618 exposed Cleo instances on Censys and 1,234 on Shodan. However, not all of these are necessarily vulnerable as their specific versions are unknown.

Shodan results exposing specific version numbers, making it easier for threat actors to identify vulnerable instances

Nearly 50% of exposed instances on Shodan are geolocated in the US

Recommended Actions

Cleo strongly advises all customers to immediately upgrade their instances of Harmony, VLTrader, and LexiCom to the latest released patch (version 5.8.0.21) to address additional discovered potential attack vectors of the vulnerability.

How Recorded Future can Help:

  • Attack Surface Intelligence - Identify internet-facing assets vulnerable to CVE-2024-50623.
  • Vulnerability Intelligence - Gain helpful context on CVE-2024-50623 to aid in patching and prioritization discussions.
  • Insikt Group - Access a Nuclei template created by Insikt Group for CVE-2024-50623 that enables defenders to test potentially vulnerable Cleo instances prior to the patched version.

Signature for CVE-2024-50623 in Recorded Future Attack Surface Intelligence

About Insikt Group: Recorded Future’s Insikt Group threat research team is comprised of analysts, linguists, and security researchers with deep government and industry experience.

Insikt Group publishes threat intelligence to the Recorded Future analyst community in blog posts and analyst notes

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/blog/cleo-mft-cve-2024-50623-vulnerability-analysis