Record summary

CVE-2020-8982 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020. RCE and file access is granted to everything hosted by ShareFile, be it on-premise or inside Citrix Cloud itself (both are internet facing). NOTE: unlike most CVEs, exploitability depends on the product version that was in use when a particular setup step was performed, NOT the product version that is in use during a current assessment of a CVE consumer's product inventory. Specifically, the vulnerability can be exploited if a storage zone was created by one of these product versions: 5.9.0, 5.8.0, 5.7.0, 5.6.0, 5.5.0, or earlier. This CVE differs from CVE-2020-7473 and CVE-2020-8983.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 30, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHCitrix ShareFile StorageZones <=5.10.x - Arbitrary File ReadCVSS 7.5

Citrix ShareFile StorageZones (aka storage zones) Controller versions through at least 5.10.x are susceptible to an unauthenticated arbitrary file read vulnerability.

Impact

An attacker can read arbitrary files on the affected system, potentially leading to unauthorized access to sensitive information.

Remediation

Upgrade Citrix ShareFile StorageZones to version 5.11 or higher to mitigate the vulnerability.

WeaknessesCWE-22
Authorsdwisiswant0
Template tagscve2020cvecitrixlfivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:citrix:sharefile_storagezones_controller:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4