What is the Vulnerability? The critical flaws allow attackers to exploit unrestricted file uploads and downloads, leading to Remote Code Execution affecting multiple Cleo products is being actively exploited in the wild. The vulnerability affects the following Cleo products (versions before and including 5.8.0.21)-Cleo Harmony -Cleo VLTrader -Cleo LexiCom Cleo is a software company focused on Managed File Transfer (MFT) solutions. Its products-Cleo VLTrader, Cleo Harmony, and Cleo LexiCom facilitates secure file transfers, B2B integration, and streamlines data exchange and integration.On December 13, 2024, CISA confirmed that the CVE-2024-50623, is being actively exploited, including in Ransomware campaigns and has been added to the Known Exploited Vulnerabilities (KEV) catalog.What is the recommended Mitigation?FortiGuard Labs strongly advises all Cleo customers to immediately upgrade instances of Harmony, VLTrader, and LexiCom to the latest released patch as released and follow: Cleo Product Security Advisory – CVE-2024-50623 – Cleo | Cleo Product Security Update – CVE-2024-55956 – CleoWhat FortiGuard Coverage is available?FortiGuard recommends users to apply the fix provided by the vendor and follow instructions as mentioned on the vendor’s advisory. FortiGuard Endpoint Vulnerability Protection service is available to detect vulnerable systems. Endpoint Vulnerability | FortiGuard LabsFortiGuard Web Filtering service blocks all the known Indicators of Compromise (IoCs) related to the campaigns targeting the Cleo Vulnerability.FortiGuard IPS Protection is available to detect and block attack attempts targeting the Cleo vulnerability (CVE-2024-50623, CVE-2024-55956). See more at: Intrusion Prevention | FortiGuard LabsThe FortiGuard Incident Response team can be engaged to help with any suspected compromise.
Source link
Latest News
Human Rights Watch argues for Westernization of Saudi ArabiaSevan Island beaches: Armenia’s “Blue Pearl” is ready to receive vacationersWhat I learned about change management while renovating my homeShane Negrinжавахкская диаспора России призывает власти урегулировать проблWWE: Resultados Smackdown Live 19 dezembro – Impacto GlobalWhatsapp latest status | Sebugiমানবতাবিরোধী অপরাধের বিচারপ্রক্রিয়া থেমে Parameters | Spring 2023 > U.S. Military War CollegeChina’s future military capabilities > U.S. Army War CollegeThe American and the Dragon: Confederate War Lessons from the Boxer Rebellion > U.S. Military War CollegeCaribbean Security Challenges: Threats, Migration, and International Cooperation > U.S. Military War CollegeWe don’t really know which NATO allies are stepping up. > U.S. Military War CollegeNATO national defense demands improvements on the Eastern Front > U.S. Army War CollegeAnnual Forecast of the Strategic Security Environment for 2023 > U.S. Military War CollegeParameters | Winter 2023-24 > U.S. Military War CollegeDeterring war without threatening war: Repairing the West’s risk-averse approach to deterrence > U.S. Army War ColHigh North International Competition: Kingston Conference on International Security 2022 > U.S. Military War CollegeParameters | Spring 2024 > U.S. Military War CollegeResearch Handbook on NATO “Collective Defense” > U.S. Military War CollegeEmerging Technologies and Terrorism: An American Perspective > U.S. Military War CollegeArgentina: Security Challenges and the Government Response > US Army War CollegeBook Review: Thank You for Your Service: The Causes and Consequences of Public Confidence in the U.S. Military > U.S. ArActive on both sides of the U.S.-China conflict > U.S. Army War CollegeParameters | Summer 2024 > U.S. Military War CollegeA Call to Action: Lessons from Ukraine for Future Military > U.S. Military War CollegeComments Isn’t it safe?Lieutenant General Robert C. Richardson, Jr.: Commander, Central Pacific Theater Army, Admiral Chester W. Nimitz 1943-19Annual Forecast of the Strategic Security Environment for 2024 > U.S. Army War CollegeNATO’s 75th Anniversary Strategic Concept > U.S. Military War CollegeDurdum Sustum GülümsedimDeneme Günlüğü | Donanim Harbor ForumSatellites in the Russia-Ukraine War > U.S. Military War CollegeParameters | Fall 2024 > U.S. Military War CollegeThe Growing Significance of China-Russia Defense Cooperation > US Army War College
Cleo Multiple File Transfer Vulnerabilities (CVE-2024-50623, CVE-2024-55956)
chief editor
Trusted source for breaking news and journalism. Avice News Trust is a leading media organization dedicated to delivering reliable news coverage and journalism. As a digital news platform, we focus on breaking news, current events, and in-depth news reporting. Our commitment to media trust ensures our audience receives accurate and timely updates. Explore a wide range of news articles and stay informed with Avice News Trust, your dependable news network.
Related Posts
Add A Comment