Cleo MFT: CVE-2024-50623
ID: 72e00b7d-294c-5042-99a6-31d5f000ab02
STIX ID: report--72e00b7d-294c-5042-99a6-31d5f000ab02
Feed Name: Recorded Future Blog
Recorded Future's Insikt Group documents CVE-2024-50623 — a critical unrestricted file upload/download vulnerability in Cleo Harmony, VLTrader, and LexiCom enabling remote code execution — and a related command-injection issue (CVE-2024-55956); both are listed in CISA's KEV, observed by GreyNoise, and have been exploited by CL0P ransomware, with many exposed instances visible on Shodan and Censys; Cleo has released patches and Recorded Future provides detection and attack-surface intelligence to identify and remediate vulnerable assets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
