CVE-2023-24489

Critical
|9.8
Exploit Available

Plain English Summary

AI-powered analysis for quick understanding

An attacker can remotely take control of the ShareFile storage zones controller without needing to log in, which could lead to unauthorized access to sensitive data. This vulnerability affects systems that are managed by customers, meaning it’s not reliant on any specific user credentials to exploit.

Technical Description

A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$13,000($5K-$15K)
Vendor Response
Grade FPatched in 961 days

Quick Information

Published

Jul 10, 2023

over 2 years ago

Last Modified

Feb 26, 2026

about 1 month ago

Vendor

citrix

Product

sharefile storage zones controller