Cleo file transfer unrestricted upload (CVE-2024-50623) — the first fix did not close it, and a second entry followed four days later
An unrestricted file upload and download vulnerability in managed file transfer products, described as leading to remote code execution. A separate entry for the same product family was added to the catalog four days later.
Key facts
- CVE IDCVE-2024-50623
- Affected (vendor / product)Cleo Multiple Products
- CWECWE-434
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2025-01-03 (U.S. federal civilian agencies, BOD 22-01)
Key points
- The affected products are managed file transfer software from Cleo, classified as unrestricted upload of file with dangerous type.
- Unrestricted upload and download is described as leading to remote code execution with elevated privileges.
- A separate entry for the same product family was added four days later under incorrect default permissions.
- The first concerns being able to place a file, the second concerns what is placed running automatically; together they let outside content run.
- Across the records this site holds as of 2026-09-04, file transfer entries with known ransomware use number 12.
1Four days apart
- 1December 13, 2024Added as an unrestricted file upload (this entry)
- 2December 17, 2024A separate entry for the same product family is added
- 3The second classIncorrect default permissions, involving the default settings of an autorun directory
- 4What that suggestsThe first response did not close it, and the same result was reachable another way
The same product family appears in the catalog twice, four days apart, under different classes of flaw. The first concerns there being no restriction on what kind of file may be placed and where; the second concerns the default settings of a directory whose contents run automatically. Being able to place something, and what is placed being run, surfaced as separate entries.
2Placing and running
Merely being able to place a file causes no immediate problem if it never runs. Equally, a location where things run automatically is not used if nothing can be placed there. Together, what is placed from outside simply runs. This site separately covers the distance between placing something and having it execute, and the same point recurs.
3Where file transfer sits
Managed file transfer products exist to move documents and data between organizations. By role they meet the outside, and what passes through them is real operational data. Across the records this site holds as of 2026-09-04, 12 unpublished entries in this grouping carry known ransomware use — not many, though the nature of what passes through tends to enlarge the effect.
4When one product is listed repeatedly in a short span
Where the same product returns to the catalog after a short interval, applying the first update may not have finished the matter. This site covers entries where later updates were said to carry more robust protection, and entries where an earlier fix was bypassed. What needs checking is not whether an update was applied but which version was reached.
Why it matters
Where the same product returns to the catalog after a short interval, applying the first update may not have finished the matter. What needs checking is which version was reached, not whether an update was applied.
FAQ
Why is one product listed twice in four days?
Is being able to place a file a small problem?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).