CVE-2021-22941
Citrix ShareFile Improper Access Control Vulnerability
Description
CVE-2021-22941 is an improper access control vulnerability in Citrix ShareFile Storage Zones Controller that allows an unauthenticated attacker to upload arbitrary files to the server. The flaw exists in the document processing functionality, where insufficient authorization checks enable an attacker to upload malicious files that can then be executed to achieve remote code execution. With an EPSS score of 83.3% (99.3rd percentile), this vulnerability has been heavily targeted. CISA has added CVE-2021-22941 to the Known Exploited Vulnerabilities catalog.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| citrix | sharefile storagezones controller | < 5.11.20 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- https://support.citrix.com/article/CTX328123(Broken Link, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22941(US Government Resource)
Weakness Type
CWE-284: Improper Access Control
CVE-2021-22941 is caused by improper access control in Citrix ShareFile Storage Zones Controller. The application fails to properly enforce authentication and authorization requirements for file upload operations, allowing an unauthenticated attacker to upload arbitrary files including executable content to the server.
Learn more: CWE-284 — Improper Access Control
Impact Analysis
CVE-2021-22941 has a CVSS v3.1 base score of 9.8 (Critical), reflecting the severe consequences of unauthenticated arbitrary file upload. The vulnerability requires no authentication, no user interaction, and can be exploited remotely with low complexity. Successful exploitation allows an attacker to upload and execute malicious files on the ShareFile Storage Zones Controller, leading to complete server compromise. The EPSS score of 83.3% (99.3rd percentile) indicates heavy exploitation activity. Citrix ShareFile is widely used for enterprise file sharing and collaboration, making compromised instances particularly valuable for accessing sensitive corporate data.
Exploit Maturity
CVE-2021-22941 has been actively exploited with public exploit code available for this vulnerability. CISA confirmed exploitation by adding it to the KEV catalog. The vulnerability has been targeted by threat actors seeking access to enterprise file sharing infrastructure and the sensitive data it contains. The EPSS score of 83.3% (99.3rd percentile) reflects the extensive exploitation activity observed against exposed ShareFile instances.
Remediation
- Apply the Citrix security update for ShareFile Storage Zones Controller that addresses CVE-2021-22941 immediately. Follow Citrix's security bulletin for specific patching instructions.
- Restrict network access to the ShareFile Storage Zones Controller, ensuring it is not directly accessible from the internet without authentication.
- Audit ShareFile Storage Zones Controllers for signs of compromise including uploaded web shells, modified configurations, unauthorized user accounts, and suspicious file activity.
- Review and strengthen access controls for the ShareFile environment, implementing multi-factor authentication and monitoring all administrative actions.
- Implement a web application firewall (WAF) in front of ShareFile deployments to filter malicious upload requests and provide an additional layer of protection.
Technical Details
CVE-2021-22941 is an improper access control vulnerability (CWE-284) in Citrix ShareFile Storage Zones Controller. The vulnerability exists in the file upload functionality of the Storage Zones Controller, which handles document storage and retrieval for the ShareFile cloud storage service. Due to insufficient authorization checks in certain upload endpoints, an unauthenticated attacker can bypass access controls and upload arbitrary files to the server. By uploading a web shell or other executable content, the attacker can then execute commands on the underlying server with the privileges of the ShareFile application. The Storage Zones Controller typically has access to all stored files and enterprise data flowing through the ShareFile platform, maximizing the impact of a successful compromise.
Frequently Asked Questions
Is CVE-2021-22941 being actively exploited?
Yes, CVE-2021-22941 has been actively exploited with public exploit code available. CISA confirmed exploitation by including it in the KEV catalog. The EPSS score of 83.3% indicates heavy exploitation targeting ShareFile deployments.
What products are affected by CVE-2021-22941?
Citrix ShareFile Storage Zones Controller is affected. The vulnerability allows unauthenticated file upload that can lead to remote code execution on the storage controller server.
How do I fix CVE-2021-22941?
Apply Citrix's security update for ShareFile Storage Zones Controller immediately. Restrict network access to the controller and audit for signs of compromise including unauthorized files and web shells.
How severe is CVE-2021-22941?
CVE-2021-22941 has a CVSS v3.1 score of 9.8 (Critical) and enables unauthenticated remote file upload leading to code execution. The EPSS score of 83.3% confirms heavy exploitation activity targeting enterprise file sharing infrastructure.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.