CVE-2021-22941
KEV ransomwarelargeUnauthenticated Remote Compromise of Citrix ShareFile Storage Zones Controller
CISA: Citrix ShareFile Improper Access Control Vulnerability
CVE-2021-22941 is an improper access control flaw (CWE-284) in Citrix ShareFile storage zones controller that allows an unauthenticated attacker to remotely compromise the controller over the network with no privileges or user interaction required (CVSS 9.8 critical). Any organization running a storage zones controller version before 5.11.20 is affected, and because these controllers handle file storage and transfer, a successful attack exposes both the server and the data it hosts. A compromised controller gives an attacker a foothold in the enterprise network, which is consistent with the flaw's known use in ransomware operations. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25 with ransomware use explicitly flagged, and its 53.6% EPSS score (99th percentile) indicates a high near-term probability of exploitation; related reporting on access brokers such as the Gold Melody group selling network access to ransomware operators underscores the active threat. Defenders should treat this as actively exploited rather than theoretical.
What to do: Upgrade storage zones controller to version 5.11.20 or later following Citrix's update instructions, prioritizing internet-exposed controllers since exploitation requires no credentials. Given confirmed ransomware use, hunt for signs of compromise on currently deployed controllers (unexpected processes, new or modified scheduled tasks and accounts, unfamiliar files) before and after patching. Restrict controller exposure to the minimum necessary network paths and monitor for follow-on lateral movement.
| Citrix ShareFile Storage Zones Controller | all versions before 5.11.20 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.
- Affected
- Citrix ShareFile
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- citrix
- Products
- sharefile storagezones controller
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H