CVE Tools

Description

Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.

In plain language

AI Act now

CVE-2021-22941 is a Citrix ShareFile security flaw that lets an attacker take over your ShareFile “storage zones controller” from the network without any login—if you run an affected version (before 5.11.20), you should act now.

Executive summary

CVE-2021-22941 is an Improper Access Control issue in the Citrix ShareFile storage zones controller that allows unauthenticated remote compromise (remote code execution / system takeover) when the controller is reachable from the network; it was added to CISA KEV and used in ransomware campaigns.

If affected, business impact
Complete server takeoverRansomware riskBusiness disruptionCustomer/drive data exposure

What to do now

  1. Check whether your Citrix ShareFile storage zones controller software is older than 5.11.20.
  2. If it is older, plan downtime and upgrade the storage zones controller to version 5.11.20 or later.
  3. Confirm the storage zones controller is not exposed to the public internet unless it must be; restrict access as tightly as your network design allows.
  4. After updating, monitor the controller host for suspicious activity and confirm the service is operating normally.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

citrix
commercial·USaka netscaler gateway firmware, xenserver, application delivery controller firmware
Citrix Systems Inc.
commercial·USaka netscaler gateway, citrix adc, citrix gateway
and 1 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Mar 25, 2022
Remediation due:Apr 15, 2022
Ransomware:Known ransomware use

Required action: Apply updates per vendor instructions.

Official Patch Available

References

and 1 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2021-22941 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows