Vulnerability record · CVE-2023-24489 · published 10 July 2023
CVE-2023-24489: Citrix ShareFile Storage Zones Controller improper access control
Citrix · Sharefile Storage Zones Controller
The customer-managed ShareFile storage zones controller contains an improper access control flaw that lets an unauthenticated attacker remotely compromise the controller. Because the controller handles file storage for the ShareFile deployment, compromise exposes the data and infrastructure it manages. The record does not specify the exact vulnerable code path or affected versions beyond the product name.
Description
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, active exploitation per CISA KEV, and a near-maximum EPSS score make this an urgent patch.
What it is
The customer-managed ShareFile storage zones controller contains an improper access control flaw that lets an unauthenticated attacker remotely compromise the controller. Because the controller handles file storage for the ShareFile deployment, compromise exposes the data and infrastructure it manages. The record does not specify the exact vulnerable code path or affected versions beyond the product name.
Impact
An unauthenticated attacker can remotely compromise the storage zones controller, gaining high confidentiality, integrity and availability impact over that system and the stored content it serves.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description confirms remote exploitation by an unauthenticated attacker.
Exploitation
Listed in CISA KEV since 2023-08-16 with a 2023-09-06 remediation due date, and EPSS gives a 30-day probability of 0.97343 (99.894th percentile), indicating active exploitation. No ransomware campaign use is recorded.
What to do
- Apply the Citrix security update for CVE-2023-24489 per vendor advisory CTX559517; if the advisory link is broken, obtain the fixed build through Citrix support.
- If patching is not possible, follow CISA KEV guidance and discontinue use of the affected storage zones controller.
- Restrict network access to the storage zones controller so it is not exposed to untrusted networks.
- Monitor Citrix guidance for any interim configuration mitigations and apply them until the patch is in place.
Detection
- Review storage zones controller logs for unexpected or anomalous requests, especially unauthenticated access attempts and unusual administrative actions.
- Hunt for signs of post-exploitation activity on the controller host, such as new processes, web shells, or unexpected outbound connections.
- Alert on network traffic to the controller from untrusted sources and on deviations from its normal request patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-24489 to the Known Exploited Vulnerabilities catalog on 16 August 2023 as "Citrix Content Collaboration ShareFile Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 6 September 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.citrix.com/article/CTX559517/sharefile-storagezones-controller-security-update-for-cve202324489 | Broken LinkVendor Advisory |
| https://support.citrix.com/article/CTX559517/sharefile-storagezones-controller-security-update-for-cve202324489 | Broken LinkVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-24489 | US Government Resource |
Track CVE-2023-24489 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-24489), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.