S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 12, 2024

CVE-2024-50623 Scanner

CVE-2024-50623 Scanner - Arbitrary File Read vulnerability in Cleo Harmony

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-50623
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
harmomyby cleo
AFFECTED< 5.8.0.21SAFE ✓≥ 5.8.0.21
vltraderby cleo
AFFECTED< 5.8.0.21SAFE ✓≥ 5.8.0.21
lexicomby cleo
AFFECTED< 5.8.0.21SAFE ✓≥ 5.8.0.21
Updated Sep 10, 2026View on NVD →
Detail

Cleo Harmony is a robust data integration platform that is widely used in various industries for secure file transfers and process automation. Businesses rely on Cleo Harmony to streamline trading partner connectivity and automate B2B communications. Its comprehensive suite supports file-based and API-based transactions, enabling the seamless exchange of enterprise data. The software is employed by IT and data management teams to ensure operational efficiency and data compliance. Companies in logistics, healthcare, manufacturing, and retail often utilize Cleo Harmony to manage and protect sensitive information. By offering end-to-end visibility and control, Cleo Harmony helps organizations to optimize their business workflows and enhance network security.

The Arbitrary File Read vulnerability allows unauthorized users to access sensitive files stored within the system. This security flaw can be exploited due to improper validation of file paths, allowing attackers to traverse directories. Exploiting this vulnerability, malicious actors can read confidential files that could contain sensitive business or personal information. The flaw exists in the way file requests are handled, lacking proper access control checks. Successfully leveraging this vulnerability can lead to unauthorized exposure of critical system files. Organizations using affected versions must address this vulnerability promptly to prevent data leaks.

The vulnerability pertains to the vulnerable endpoint located at '/Synchronization', which permits arbitrary file read operations. The parameter 'path' in the request is not adequately sanitized, allowing for directory traversal. Attackers can manipulate the 'path' to access restricted files beyond their original scope. By adjusting requests to include '../../../' sequences, attackers can navigate through directories and retrieve sensitive files, such as configuration files. The lack of input validation on this parameter significantly contributes to the exploitability of the vulnerability. Proper sanitization and validation mechanisms must be enforced to mitigate such risks.

Exploiting this vulnerability can lead to severe consequences, including unauthorized access to sensitive data. Attackers could read configuration files, user data, or other critical system files, potentially leading to further exploitation or system compromise. Companies may face data breaches, resulting in financial loss and reputational damage. Additionally, accessing exposed files might allow attackers to gather information useful for launching more targeted attacks. The resulting security compromise could weaken the integrity and confidentiality of the organization's data handling systems.

Solution Advice
  • Ensure all file paths are properly sanitized and validated to prevent directory traversal.
  • Implement strict access controls to limit the exposure of sensitive files.
  • Regularly update to the latest version to incorporate security patches and improvements.
  • Conduct periodic security audits to identify and address potential vulnerabilities.
  • Deploy intrusion detection systems to monitor and alert on unusual file access patterns.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-50623 Scanner - Arbitrary File Read vulnerability in Cleo Harmony | S4E