Exploited Known exploited (KEV) Ransomware use CVE-2024-50623

Cleo file transfer unrestricted upload (CVE-2024-50623) — the first fix did not close it, and a second entry followed four days later

Cleo Multiple Products Added to KEV Dec 13, 2024 Federal remediation due 2025-01-03

An unrestricted file upload and download vulnerability in managed file transfer products, described as leading to remote code execution. A separate entry for the same product family was added to the catalog four days later.

Key facts

  • CVE IDCVE-2024-50623
  • Affected (vendor / product)Cleo Multiple Products
  • CWECWE-434
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2025-01-03 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • The affected products are managed file transfer software from Cleo, classified as unrestricted upload of file with dangerous type.
  • Unrestricted upload and download is described as leading to remote code execution with elevated privileges.
  • A separate entry for the same product family was added four days later under incorrect default permissions.
  • The first concerns being able to place a file, the second concerns what is placed running automatically; together they let outside content run.
  • Across the records this site holds as of 2026-09-04, file transfer entries with known ransomware use number 12.

1Four days apart

  1. 1December 13, 2024Added as an unrestricted file upload (this entry)
  2. 2December 17, 2024A separate entry for the same product family is added
  3. 3The second classIncorrect default permissions, involving the default settings of an autorun directory
  4. 4What that suggestsThe first response did not close it, and the same result was reachable another way

The same product family appears in the catalog twice, four days apart, under different classes of flaw. The first concerns there being no restriction on what kind of file may be placed and where; the second concerns the default settings of a directory whose contents run automatically. Being able to place something, and what is placed being run, surfaced as separate entries.

2Placing and running

The first entryThe second entry
No restriction on file type or locationA problem in default settings
The issue is that placement is possibleThe issue is that what is placed runs automatically
Addressed by checking inputAddressed by revisiting configuration

Merely being able to place a file causes no immediate problem if it never runs. Equally, a location where things run automatically is not used if nothing can be placed there. Together, what is placed from outside simply runs. This site separately covers the distance between placing something and having it execute, and the same point recurs.

3Where file transfer sits

File transfer grouping across the records this site holds as of 2026-09-0412 unpublished entries with known ransomware useBy their nature these products meet the outside
Due date here21 daysAdded December 13, 2024, due January 3, 2025
Due date for the second entry21 daysAdded December 17, 2024, due January 7, 2025

Managed file transfer products exist to move documents and data between organizations. By role they meet the outside, and what passes through them is real operational data. Across the records this site holds as of 2026-09-04, 12 unpublished entries in this grouping carry known ransomware use — not many, though the nature of what passes through tends to enlarge the effect.

4When one product is listed repeatedly in a short span

Where the same product returns to the catalog after a short interval, applying the first update may not have finished the matter. This site covers entries where later updates were said to carry more robust protection, and entries where an earlier fix was bypassed. What needs checking is not whether an update was applied but which version was reached.

Why it matters

Where the same product returns to the catalog after a short interval, applying the first update may not have finished the matter. What needs checking is which version was reached, not whether an update was applied.

FAQ

Why is one product listed twice in four days?
They are two entries of different classes. It suggests the first response did not close the matter and the same result was reachable another way.
Is being able to place a file a small problem?
On its own it causes no immediate problem if nothing runs. But where a location runs its contents automatically, the two together let outside content run.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Security#CISA#KEV#File transfer#File upload
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.