Vulnerability record · CVE-2024-50623 · published 28 October 2024
CVE-2024-50623: Cleo Harmony, VLTrader, LexiCom Unrestricted File Upload RCE
Cleo · Harmony
Cleo Harmony, VLTrader, and LexiCom before 5.8.0.21 allow unrestricted file upload and download, which can lead to remote code execution. The flaw is remotely reachable without authentication, making it a severe risk for internet-facing file transfer servers.
Description
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, active exploitation in CISA KEV with known ransomware use, and near-certain EPSS probability make this an urgent threat.
What it is
Cleo Harmony, VLTrader, and LexiCom before 5.8.0.21 allow unrestricted file upload and download, which can lead to remote code execution. The flaw is remotely reachable without authentication, making it a severe risk for internet-facing file transfer servers.
Impact
An unauthenticated attacker can upload and execute arbitrary files, gaining remote code execution on the affected server. This can lead to full system compromise, data theft, and deployment of ransomware.
Attack surface
The vulnerability is network-reachable (AV:N) with no authentication (PR:N) and no user interaction (UI:N), based on the CVSS vector. Any exposed Cleo Harmony, VLTrader, or LexiCom instance before 5.8.0.21 is potentially reachable.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2024-12-13 with known ransomware campaign use, and EPSS shows a 30-day probability of 0.98607 (99.9th percentile), indicating active exploitation.
What to do
- Upgrade Cleo Harmony, VLTrader, and LexiCom to version 5.8.0.21 or later immediately.
- If patching is not possible, follow CISA's required action to apply vendor mitigations or discontinue use of the product.
- Restrict network access to Cleo file transfer services to trusted sources only.
- Monitor for and block unauthorized file uploads to Cleo application directories.
- Review systems for signs of compromise and isolate affected hosts if indicators are found.
Detection
- Monitor for unexpected file creation or modification in Cleo web-accessible directories.
- Inspect web server and application logs for suspicious POST requests or file upload attempts.
- Use file integrity monitoring to alert on new executable files in Cleo installation paths.
- Hunt for outbound connections or process execution spawned by Cleo services that are unusual.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-50623 to the Known Exploited Vulnerabilities catalog on 13 December 2024 as "Cleo Multiple Products Unrestricted File Upload Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 3 January 2025.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.cleo.com/hc/en-us/articles/27140294267799-Cleo-Product-Security-Advisory | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-50623 | US Government Resource |
Track CVE-2024-50623 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-50623), CISA KEV, FIRST EPSS (scores of 2026-09-20). This page is refreshed as NVD updates the record.