Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-7473


In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated attackers to access the documents and folders of ShareFile users. NOTE: unlike most CVEs, exploitability depends on the product version that was in use when a particular setup step was performed, NOT the product version that is in use during a current assessment of a CVE consumer's product inventory. Specifically, the vulnerability can be exploited if a storage zone was created by one of these product versions: 5.9.0, 5.8.0, 5.7.0, 5.6.0, 5.5.0, or earlier. This CVE differs from CVE-2020-8982 and CVE-2020-8983 but has essentially the same risk.


Published

2020-05-07T14:15:11.947

Last Modified

2024-11-21T05:37:12.967

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application citrix sharefile_storagezones_controller ≤ 5.5.0 Yes
Application citrix sharefile_storagezones_controller 5.6.0 Yes
Application citrix sharefile_storagezones_controller 5.7.0 Yes
Application citrix sharefile_storagezones_controller 5.8.0 Yes
Application citrix sharefile_storagezones_controller 5.9.0 Yes

References