CVE-2023-24489: Citrix Content Collaboration ShareFile Improper Access Control Vulnerability
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.
Other sources
Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of Citrix Content Collaboration and Citrix ShareFile Storage Zones Controller if mitigations are unavailable.
Event History
Frequently Asked Questions
What is CVE-2023-24489?
CVE-2023-24489 is a vulnerability found in the customer-managed ShareFile storage zones controller, which could allow an unauthenticated attacker to compromise the controller remotely.
What software is affected by CVE-2023-24489?
The Citrix Content Collaboration product, specifically the customer-managed ShareFile storage zones controller version up to 5.11.24, is affected by CVE-2023-24489.
How severe is CVE-2023-24489?
CVE-2023-24489 has a severity level of critical with a score of 9.
How do I fix CVE-2023-24489?
To fix CVE-2023-24489, it is recommended to update the Citrix Content Collaboration ShareFile storage zones controller to a version beyond 5.11.24. Please refer to the provided reference for more information.
Where can I find more information about CVE-2023-24489?
More information about CVE-2023-24489 can be found in the provided reference: https://support.citrix.com/article/CTX559517/sharefile-storagezones-controller-security-update-for-cve202324489