VulnerabilityAnalyzed
CVE-2021-22941
Citrix ShareFile Improper Access Control Vulnerability
KEVCRITICAL 9.8EPSS 53.6%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 53.59% probability · 99th percentile
- CISA KEV
- Listed 25 March 2022 · due 15 April 2022 · used in ransomware campaigns
- Weakness
- CWE-284
- Affected
- citrix/sharefile storagezones controller
- Source
- support@hackerone.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-22941
References
- https://support.citrix.com/article/CTX328123Broken Link, Vendor Advisory
- https://support.citrix.com/article/CTX328123Broken Link, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22941US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.