Junglewise Threat Intelligence

CVE-2021-22941: Citrix ShareFile Improper Access Control Vulnerability

CVE-2021-22941 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Vendors: Citrix.

Executive brief

Improper Access Control in Citrix ShareFile storage zones controller allows an unauthenticated attacker to remotely compromise the controller. The vulnerability stems from insufficient validation of access permissions, potentially leading to full system compromise.

Affected products

  • Citrix ShareFile storage zones controller before 5.11.20

Timeline

  • 2021-09-23: disclosed: NVD Published Date
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog