CVE-2019-7218: Medium severity citrix vulnerability
Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like google authenticator) is able to bypass the first authentication phase (username/password mechanism) and log-in using username/otp combination only (phase 2 of 2FA).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7218?
CVE-2019-7218 is rated as a medium severity vulnerability.
How do I fix CVE-2019-7218?
To fix CVE-2019-7218, upgrade Citrix ShareFile to version 19.23 or later.
What is the impact of CVE-2019-7218?
CVE-2019-7218 allows an attacker to downgrade from two-factor authentication to one-factor authentication, compromising account security.
Who is affected by CVE-2019-7218?
CVE-2019-7218 affects users of Citrix ShareFile versions prior to 19.23.
What type of vulnerability is CVE-2019-7218?
CVE-2019-7218 is a security vulnerability related to inadequate two-factor authentication protection.