LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-55956: Cleo Multiple Products Unauthenticated File Upload Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 17, 2024
CVSS 9.8 · Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
9.8
CVSS score
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jan 7, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-55956 to its Known Exploited Vulnerabilities catalog on Dec 17, 2024, with a federal patch deadline of Jan 7, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

CVE-2024-55956 is an unauthenticated file upload vulnerability affecting Cleo Harmony, VLTrader, and LexiCom managed file transfer products. An unauthenticated attacker can import and execute arbitrary bash or PowerShell commands on the host by leveraging the default settings of the Autorun directory. This matters because these products often sit at the edge of enterprise file-exchange workflows, so successful abuse can give remote code execution on systems that handle sensitive transfers. The vulnerability has known ransomware use, raising the stakes for rapid response.

How it works

The weakness is classified as CWE-276 (Incorrect Default Permissions). In practice it manifests as an unrestricted file upload that an unauthenticated user can exploit against the default Autorun directory configuration. An attacker who can reach the affected service can place content that the product then treats as executable, resulting in arbitrary bash or PowerShell command execution on the host. Exact request paths, payloads, or trigger conditions are not detailed here; defenders must confirm the precise mechanics against the vendor advisory. Because the attack requires no prior authentication, any internet-exposed or poorly segmented instance is immediately reachable.

Am I affected? How to find it in your systems

Cleo Harmony, VLTrader, and LexiCom are managed file transfer (MFT) platforms commonly deployed for B2B data exchange, EDI, and secure file movement. They typically run on Windows or Linux servers inside DMZs or dedicated transfer zones, often with web or API listeners facing partners or the internet.

How to remediate

Apply the vendor-supplied update or mitigations first. CISA directs organizations to apply mitigations per vendor instructions or to discontinue use of the product if mitigations are unavailable. After patching, re-verify that the Autorun directory no longer permits unauthenticated writes or automatic execution of uploaded content. Harden the remaining configuration by restricting write access to the Autorun path, enforcing least-privilege service accounts, and ensuring the MFT listeners are not exposed beyond necessary partner networks. Validate the fix with a controlled test that attempts an unauthenticated upload and confirms it is rejected.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities of this class, especially those with known ransomware use, frequently lead to full host compromise and subsequent data theft or encryption. If you discover evidence of exploitation, treat the host as breached, isolate it, preserve forensic artifacts, and begin incident-response procedures. As a quick check for personal or organizational email addresses that may already appear in known breach data, you can run a free exposure scan of those addresses against public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCleo · Multiple Products
WeaknessCWE-77
CVSS base score9.8 (Critical)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
PublishedDec 13, 2024
Added to CISA KEVDec 17, 2024
Federal patch deadlineJan 7, 2025
Known ransomware useYes
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities