Sharefile Storage Zones Controller
Vendor:
First CVE: Sep 26, 2018 · Active for 7 years
9
Total CVEs
Bottom 1%
2.3
Avg CVEs / Year
Bottom 1%
7.4
Avg CVSS
Higher Avg CVSS than 88% of tracked products
22.2%
KEV Rate
Higher KEV Rate than 99% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Sharefile Storage Zones Controller over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 26, 2018
7 years ago
Most Recent CVE
Jul 10, 2023
1,114 days ago
CVE Severity & Scoring
Sharefile Storage Zones Controller9 CVEs
11%
11%
44%
33%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None7 (77.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24489CRITICAL A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise t | Jul 10, 2023 | 9.8 | 97 | YES | YES |
CVE-2021-22941CRITICAL Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller. | Sep 23, 2021 | 9.8 | 89 | YES | NO |
CVE-2020-8982HIGH An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of | May 7, 2020 | 7.5 | 50 | NO | YES |
CVE-2021-22891CRITICAL A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow unauthenticated remote compromise | May 27, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-8983HIGH An arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, whic | May 7, 2020 | 7.5 | 27 | NO | NO |
CVE-2020-7473HIGH In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated | May 7, 2020 | 7.5 | 27 | NO | NO |
CVE-2021-22932HIGH An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes the ShareFile file encryption option to become disabled if | Aug 16, 2021 | 7.5 | 24 | NO | NO |
CVE-2018-16969MEDIUM Citrix ShareFile StorageZones Controller before 5.4.2 has Information Exposure Through an Error Message. | Sep 26, 2018 | 4.3 | 17 | NO | NO |
Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal. | Sep 26, 2018 | 3.1 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
2 CVEs
22.2% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
22.2% of CVEs· 99th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Sharefile Storage Zones Controller
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.9.0 | 3 | 7.5 | 15.3% | 0 | 1 |
| 5.8.0 | 3 | 7.5 | 15.3% | 0 | 1 |
| 5.7.0 | 3 | 7.5 | 15.3% | 0 | 1 |
| 5.6.0 | 3 | 7.5 | 15.3% | 0 | 1 |