CVE-2021-22941
Citrix ShareFile Improper Access Control Vulnerability
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
Yes
*KEV
Decision
-
*SSVC
Descriptions
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.
Un control de acceso inapropiado en Citrix ShareFile storage zones controller versiones anteriores a 5.11.20, podrĂa permitir a un atacante no autenticado comprometer remotamente el controlador de zonas de almacenamiento
Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-01-06 CVE Reserved
- 2021-09-23 CVE Published
- 2021-10-12 First Exploit
- 2022-03-25 Exploited in Wild
- 2022-04-15 KEV Due Date
- 2024-06-08 EPSS Updated
- 2024-08-03 CVE Updated
CWE
- CWE-284: Improper Access Control
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/hoavt184/CVE-2021-22941 | 2021-10-12 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.citrix.com/article/CTX328123 | 2022-08-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Citrix Search vendor "Citrix" | Sharefile Storagezones Controller Search vendor "Citrix" for product "Sharefile Storagezones Controller" | < 5.11.20 Search vendor "Citrix" for product "Sharefile Storagezones Controller" and version " < 5.11.20" | - |
Affected
|