Information Disclosure Vulnerability in Citrix ShareFile by Citrix
CVE-2021-22932

7.5HIGH

Key Information:

Vendor
Citrix
Vendor
CVE Published:
16 August 2021

Summary

An issue has been detected in the CTX269106 mitigation tool for the Citrix ShareFile storage zones controller, where the 'Enable Encryption' feature may inadvertently be disabled if previously selected. This affects users who have enabled encryption and subsequently run the mitigation tool without reactivating the setting. Users who either did not apply the mitigation tool or reactivated the encryption option after running it are not impacted. Proper attention to configuration settings is essential to maintain encryption and secure data.

Affected Version(s)

Citrix ShareFile Storage Zones Controller Citrix ShareFile storage zones controller CTX269106 mitigation tool

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.