Vulnerability record · CVE-2021-22941 · published 23 September 2021
CVE-2021-22941: Citrix ShareFile storage zones controller improper access control
Citrix · Sharefile Storagezones Controller
Citrix ShareFile storage zones controller before 5.11.20 contains an improper access control flaw (CWE-284) that can let an unauthenticated attacker remotely compromise the controller. Because the controller sits in the storage path for ShareFile data, a compromise exposes the file storage infrastructure rather than a single user account.
Description
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 unauthenticated remote compromise, KEV listing with known ransomware use, and very high EPSS probability make this an urgent patch target.
What it is
Citrix ShareFile storage zones controller before 5.11.20 contains an improper access control flaw (CWE-284) that can let an unauthenticated attacker remotely compromise the controller. Because the controller sits in the storage path for ShareFile data, a compromise exposes the file storage infrastructure rather than a single user account.
Impact
An unauthenticated attacker can remotely compromise the storage zones controller, gaining high confidentiality, integrity and availability impact on that host. In practice this means control of the component that brokers access to stored ShareFile data.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed storage zones controller instance is in scope.
Exploitation
Listed in CISA KEV since 2022-03-25 with known ransomware campaign use, and EPSS 30-day probability is about 0.536 (98.9th percentile), indicating active exploitation is expected. The vendor advisory reference is tagged as a broken link, so consult CISA KEV for the required action.
What to do
- Upgrade Citrix ShareFile storage zones controller to 5.11.20 or later as instructed by the vendor advisory.
- If immediate patching is not possible, remove the controller from direct internet exposure and restrict access to trusted networks.
- Verify the controller is not reachable from untrusted networks and review firewall or load balancer rules for unintended exposure.
- Rotate credentials and secrets used by the storage zones controller after patching, in case of prior compromise.
- Monitor CISA KEV for updated guidance and confirm remediation against the listed due date.
Detection
- Search web and proxy logs for anomalous requests to storage zones controller endpoints from unauthenticated or unexpected source IPs.
- Review controller and host logs for unexpected process creation, file writes, or configuration changes around the controller service.
- Hunt for signs of post-exploitation on controller hosts, including new accounts, scheduled tasks, or outbound connections to unfamiliar hosts.
- Inventory all storage zones controller instances and confirm version is 5.11.20 or later.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-22941 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Citrix ShareFile Improper Access Control Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.citrix.com/article/CTX328123 | Broken LinkVendor Advisory |
| https://support.citrix.com/article/CTX328123 | Broken LinkVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22941 | US Government Resource |
Track CVE-2021-22941 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22941), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.