Junglewise Threat Intelligence

CVE-2023-24489: Citrix Content Collaboration ShareFile Improper Access Control Vulnerability

CVE-2023-24489 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-08-16

Vendors: Citrix.

Executive brief

Citrix Content Collaboration ShareFile contains an improper access control vulnerability in the customer-managed storage zones controller. An unauthenticated remote attacker can exploit this to compromise the controller, potentially leading to full system takeover.

Affected products

  • Citrix ShareFile Storage Zones Controller < 5.11.24

Timeline

  • 2023-07-10: disclosed: NVD Published Date
  • 2023-08-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-08-16: advisory