🔙 목록으로 돌아가기

CVE-2023-24489: Citrix ShareFile StorageZones Controller - Unauthenticated Remote Code Execution

TitleCitrix ShareFile StorageZones Controller - Unauthenticated Remote Code Execution
AuthorDhiyaneshDK,dwisiswant0
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationApply the necessary security patches or updates provided by Citrix to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.94389
CVE IDCVE-2023-24489
CWE IDCWE-284,NVD-CWE-Other
Shodan Querytitle:"ShareFile Storage Server"http.title:"sharefile storage server"
Fofa Querytitle="sharefile storage server"
Tags cve2023 cve sharefile rce intrusive fileupload kev citrix vkev vuln

🔍 Vulnerability Description

A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.

🌐 HTTP Request

No request captured.

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-24489.yaml

🦈 Packet Capture: ⬇️ Download cve-2023-24489.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A