
=====================================================================

                             CERT-Renater

                 Note d'Information No. 2021/VULN465
_____________________________________________________________________

DATE                : 15/09/2021

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Citrix ShareFile storage zones
                         controller versions prior to 5.11.20.

=====================================================================
https://support.citrix.com/article/CTX328123
_____________________________________________________________________

CTX328123
Citrix ShareFile Storage Zones Controller Security Update

Applicable Products

    ShareFile


Description of Problem
A security issue has been identified in Citrix ShareFile storage zones
controller which, if exploited, would allow an unauthenticated attacker
to remotely compromise the storage zones controller.

The issue has been given the following identifier:

CVE-ID	     Description     Type        Pre-requisites

CVE-2021-22941	Improper resource control allows unauthenticated remote
compromise	CWE-284: Improper Access Control	Network access to the
ShareFile storage zones controller

All currently supported versions of Citrix ShareFile storage zones
controller before 5.11.20 are affected by this issue.

Customers using Citrix-managed storage zones in the cloud are not
affected by this issue.


What Customers Should Do

This issue has been addressed in the following versions of Citrix
ShareFile storage zones controller:

    ShareFile storage zones controller 5.11.20 and later versions


Citrix strongly recommends that customers upgrade to a fixed version as
soon as possible.

The latest version of Citrix ShareFile storage zones controller is
available from the following Citrix website location:
https://www.citrix.com/downloads/sharefile/


Acknowledgements

Citrix would like to thank Markus Wulftange of Code White GmbH for
working with us to help protect Citrix customers.


What Citrix is Doing

Citrix is notifying customers and channel partners about this potential
security issue. This article is also available from the Citrix Knowledge
Center at https://support.citrix.com/.


Obtaining Support on This Issue

If you require technical assistance with this issue, please contact
Citrix Technical Support. Contact details for Citrix Technical Support
are available at https://www.citrix.com/support/open-a-support-case/.


Reporting Security Vulnerabilities to Citrix

Citrix welcomes input regarding the security of its products and
considers any and all potential vulnerabilities seriously. For details
on our vulnerability response process and guidance on how to report
security-related issues to Citrix, please see the following webpage:
https://www.citrix.com/about/trust-center/vulnerability-process.html.


Disclaimer

This document is provided on an "as is" basis and does not imply any
kind of guarantee or warranty, including the warranties of
merchantability or fitness for a particular use. Your use of the
information on the document is at your own risk. Citrix reserves the
right to change or update this document at any time.


Changelog

Date                Change
2021-09-14          Initial Publication


=========================================================
+ CERT-RENATER       |    tel : 01-53-94-20-44          +
+ 23/25 Rue Daviel   |    fax : 01-53-94-20-41          +
+ 75013 Paris        |    email:cert@support.renater.fr +
=========================================================


