SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-22941

Citrix ShareFile Improper Access Control Vulnerability

KEVCRITICAL 9.8EPSS 53.6%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
53.59% probability · 99th percentile
CISA KEV
Listed 25 March 2022 · due 15 April 2022 · used in ransomware campaigns
Weakness
CWE-284
Affected
citrix/sharefile storagezones controller
Source
support@hackerone.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-22941

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.