Information Disclosure Vulnerability in Citrix ShareFile by Citrix
CVE-2021-22932
7.5HIGH
Key Information:
- Vendor
- Citrix
- Vendor
- CVE Published:
- 16 August 2021
Summary
An issue has been detected in the CTX269106 mitigation tool for the Citrix ShareFile storage zones controller, where the 'Enable Encryption' feature may inadvertently be disabled if previously selected. This affects users who have enabled encryption and subsequently run the mitigation tool without reactivating the setting. Users who either did not apply the mitigation tool or reactivated the encryption option after running it are not impacted. Proper attention to configuration settings is essential to maintain encryption and secure data.
Affected Version(s)
Citrix ShareFile Storage Zones Controller Citrix ShareFile storage zones controller CTX269106 mitigation tool
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved