CVE ID
CVE-2024-50623
Vulnerability Name
Cleo Multiple Products Unrestricted File Upload Vulnerability
- Project: Cleo
- Product: Multiple Products
Date
- Date Added: 2024-12-13
- Due Date: 2025-01-03
Description
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.
Known To Be Used in Ransomware Campaigns?
Known
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Update ; https://nvd.nist.gov/vuln/detail/CVE-2024-50623
Related Security News
- Harvard investigating breach linked to Oracle zero-day exploit
- Clop exploited Oracle zero-day for data theft since early August
- Oracle patches EBS zero-day exploited in Clop data theft attacks
- Oracle links Clop extortion attacks to July 2025 vulnerabilities
- Clop extortion emails claim theft of Oracle E-Business Suite data
- Emails claim Oracle data theft in new Clop-linked extortion campaign
- Food giant WK Kellogg discloses data breach linked to Clop ransomware
- Retail giant Sam’s Club investigates Clop ransomware breach claims
- Western Alliance Bank notifies 21,899 customers of data breach
- Leaked Black Basta Ransomware Chat Logs Reveal Inner Workings and Internal Conflicts