QID 378615

Date Published: 2023-06-26

QID 378615: Citrix ShareFile StorageZones Controller Remote Code Execution (RCE) Vulnerability (CTX559517)

A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.

Affected Versions:
This vulnerability affects all currently supported versions of customer-managed ShareFile storage zones controller before version 5.11.24.

QID Detection Logic:
This QID checks for vulnerable version of Citrix ShareFile StorageZones Controller by checking the version of StorageCenter.dll.

Successful exploitation of the vulnerability may result in Remote Code Execution and total system compromise.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade to Citrix ShareFile StorageZones Controller version 5.11.24 or later. For more information please refer to CTX559517

    CVEs related to QID 378615

    Software Advisories
    Advisory ID Software Component Link
    CTX559517 URL Logo support.citrix.com/article/CTX559517/sharefile-storagezones-controller-security-update-for-cve202324489