CVE-2021-22941 is a critical improper access control vulnerability affecting Citrix ShareFile storage zones controllers prior to version 5.11.20. This flaw allows an unauthenticated attacker to remotely compromise the controller, leading to complete loss of confidentiality, integrity, and availability. With a CVSS score of 9.8, it is easily exploitable over the network with low attack complexity. This vulnerability is actively exploited in the wild, including in known ransomware campaigns, and has garnered significant community discussion, despite a lack of public exploit code on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.11.20CPE matchmatch criteria | cpe:2.3:a:citrix:sharefile_storagezones_controller:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.