Cleo Multiple File Transfer Vulnerabilities
What is the Vulnerability? | The critical flaws allow attackers to exploit unrestricted file uploads and downloads, leading to Remote Code Execution affecting multiple Cleo products is being actively exploited in the wild. |
What is the recommended Mitigation? | FortiGuard Labs strongly advises all Cleo customers to immediately upgrade instances of Harmony, VLTrader, and LexiCom to the latest released patch as released and follow: Cleo Product Security Advisory - CVE-2024-50623 – Cleo | Cleo Product Security Update - CVE-2024-55956 – Cleo |
What FortiGuard Coverage is available? |
|
Additional Resources
Cleo Product Security Advisory - CVE-2024-50623 – Cleo
Cleo Product Security Update - CVE-2024-55956 – Cleo
NVD - CVE-2024-55956
Clop ransomware claims responsibility for Cleo data theft attacks
Endpoint Vulnerability | FortiGuard Labs
Intrusion Prevention | FortiGuard Labs