RSS   Vulnerabilities for
'Sharefile storagezones controller'
   RSS

2020-05-07
 
CVE-2020-8983

CWE-22
 

 
An arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, which allows remote code execution. RCE and file access is granted to everything hosted by ShareFile, be it on-premise or inside Citrix Cloud itself (both are internet facing). NOTE: unlike most CVEs, exploitability depends on the product version that was in use when a particular setup step was performed, NOT the product version that is in use during a current assessment of a CVE consumer's product inventory. Specifically, the vulnerability can be exploited if a storage zone was created by one of these product versions: 5.9.0, 5.8.0, 5.7.0, 5.6.0, 5.5.0, or earlier. This CVE differs from CVE-2020-7473 and CVE-2020-8982.

 
 
CVE-2020-8982

CWE-22
 

 
An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020. RCE and file access is granted to everything hosted by ShareFile, be it on-premise or inside Citrix Cloud itself (both are internet facing). NOTE: unlike most CVEs, exploitability depends on the product version that was in use when a particular setup step was performed, NOT the product version that is in use during a current assessment of a CVE consumer's product inventory. Specifically, the vulnerability can be exploited if a storage zone was created by one of these product versions: 5.9.0, 5.8.0, 5.7.0, 5.6.0, 5.5.0, or earlier. This CVE differs from CVE-2020-7473 and CVE-2020-8983.

 
 
CVE-2020-7473

CWE-22
 

 
In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated attackers to access the documents and folders of ShareFile users. NOTE: unlike most CVEs, exploitability depends on the product version that was in use when a particular setup step was performed, NOT the product version that is in use during a current assessment of a CVE consumer's product inventory. Specifically, the vulnerability can be exploited if a storage zone was created by one of these product versions: 5.9.0, 5.8.0, 5.7.0, 5.6.0, 5.5.0, or earlier. This CVE differs from CVE-2020-8982 and CVE-2020-8983 but has essentially the same risk.

 

 >>> Vendor: Citrix 94 Products
Metaframe
Winframe
Nfuse
Ica client
Access essentials
Metaframe presentation server
Presentation server
Metaframe client
Program neighborhood agent
Metaframe password manager
Ica program neighborhood client
Metaframe secure access manager
Program neighborhood client
Access gateway
Presentation server client
Endpoint analysis client
Netscaler
Edgesight for endpoints
Edgesight for netscaler
Edgesight for presentation server
Web interface
Desktop server
Citrix presentation server
Xenserver
XP
XEN
Xenapp
Deterministic network enhancer
Broadcast server
Netscaler access gateway firmware
Secure gateway
Licensing
Xencenterweb
Online plug-in for mac
Online plug-in for windows
Receiver for iphone
Ica client for linux
Ica client for solaris
Online plug-in for mac for xenapp & xendesktop
Online plug-in for windows for xenapp & xendesktop
Receiver for windows mobile
Licensing administration console
Provisioning services
Cloudstack
Xendesktop
Netscaler access gateway
Xenclient xt
Cloudportal services manager
Netscaler application delivery controller
Netscaler application delivery controller firmware
Gotomeeting
Xenmobile device manager
Xenmobile device manager mdm
Sharefile mobile
Sharefile mobile for tablets
Vdi-in-a-box
Cloudplatform
Access gateway plug-in
Xenmobile
Netscaler gateway firmware
Command center
Netscaler service delivery appliance service vm
Xenmobile server
Netscaler gateway 11.0 firmware
Ios receiver
Worx home
Xenmobile mdx toolkit
Linux virtual delivery agent
License server
License server vpx
Receiver desktop
Netscaler sd-wan
Netscaler gateway
Application delivery controller firmware
Sd-wan
Sharefile
Receiver
Appdna
Gateway firmware
Citrix sd-wan center
Netscaler sd-wan center
Sharefile storagezones controller
Workspace app
Gateway plug-in for linux
Workspace
Gateway plug-in
Virtual apps and desktops
Secure mail
Cloud connector
Gateway
Sd-wan wanop
Application delivery management
Federated authentication service
Storefront server


Copyright 2024, cxsecurity.com

 

Back to Top