| Title | Citrix ShareFile StorageZones Controller - Unauthenticated Remote Code Execution |
|---|---|
| Author | DhiyaneshDK,dwisiswant0 |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system. |
| Remediation | Apply the necessary security patches or updates provided by Citrix to mitigate this vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.94389 |
| CVE ID | CVE-2023-24489 |
| CWE ID | CWE-284,NVD-CWE-Other |
| Shodan Query | title:"ShareFile Storage Server"http.title:"sharefile storage server" |
| Fofa Query | title="sharefile storage server" |
| Tags | cve2023 cve sharefile rce intrusive fileupload kev citrix vkev vuln |
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.
No request captured.
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-24489.yaml
🦈 Packet Capture: ⬇️ Download cve-2023-24489.pcap
N/AN/A