ShareFile Documents Unauthenticated Access (CVE-2020-7473)

high Nessus Plugin ID 137001

Synopsis

The Citrix Sharefile Storage Zones Controller instance found on the remote host is affected by an unauthenticated access vulnerability.

Description

Security issues have been identified in customer-managed Citrix ShareFile storage zone controllers. These vulnerabilities, if exploited, would allow an unauthenticated attacker to compromise the storage zones controller potentially giving an attacker the ability to access ShareFile users’ documents and folders.

Storage zones created using a vulnerable version of the storage zones controller are at risk even if the storage zones controller has been subsequently updated.

Solution

See vendor advisory.

See Also

https://support.citrix.com/article/CTX269106

Plugin Details

Severity: High

ID: 137001

File Name: citrix_sharefile_controller_CVE-2020-7473.nbin

Version: 1.68

Type: remote

Family: Misc.

Published: 6/2/2020

Updated: 11/22/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2020-8983

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:citrix:sharefile

Required KB Items: installed_sw/Citrix ShareFile StorageZones Controller

Exploit Ease: No known exploits are available

Patch Publication Date: 5/5/2020

Vulnerability Publication Date: 5/5/2020

Reference Information

CVE: CVE-2020-7473, CVE-2020-8982, CVE-2020-8983