CVE-2021-22941
Description
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.
In plain language
AI Act nowCVE-2021-22941 is a Citrix ShareFile security flaw that lets an attacker take over your ShareFile “storage zones controller” from the network without any login—if you run an affected version (before 5.11.20), you should act now.
CVE-2021-22941 is an Improper Access Control issue in the Citrix ShareFile storage zones controller that allows unauthenticated remote compromise (remote code execution / system takeover) when the controller is reachable from the network; it was added to CISA KEV and used in ransomware campaigns.
What to do now
- Check whether your Citrix ShareFile storage zones controller software is older than 5.11.20.
- If it is older, plan downtime and upgrade the storage zones controller to version 5.11.20 or later.
- Confirm the storage zones controller is not exposed to the public internet unless it must be; restrict access as tightly as your network design allows.
- After updating, monitor the controller host for suspicious activity and confirm the service is operating normally.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2021-22941 and every CVE in our database. Create a free account — no credit card required.
Create Free Account