CVE-2020-8982 Scanner

Targets the StorageZones Controller's web interface to read arbitrary files without authentication, exposing sensitive data like configuration files.

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

30 seconds

Time Interval

1 month 4 days

Scan only one

URL

Toolbox

Citrix ShareFile StorageZones Controller is an enterprise file-sharing solution that allows organizations to host their own storage zones, either on-premises or in the cloud. It provides secure data residency and compliance by enabling IT teams to manage where files are stored. This product is widely used by businesses that require granular control over their data, integrating with Citrix Workspace and other collaboration tools.

CVE-2020-8982 is an arbitrary file read vulnerability that arises due to improper input validation in the StorageZones Controller's web server. The flaw allows an unauthenticated attacker to traverse directories and read any file on the system, including sensitive configuration files, credentials, and private keys. This vulnerability exists because the software fails to sanitize user-supplied paths before accessing files.

Specifically, the vulnerability is triggered through the StorageZones Controller's HTTP endpoint that handles file requests. By manipulating the path parameter in a GET request, an attacker can read files outside the intended web root directory. For example, sending a request like /path/../../etc/passwd can expose system files. The issue affects all versions up to 5.10.x, including the latest releases as of May 2020.

If exploited, an attacker can gain access to critical system files, such as database configurations, SSL certificates, and user credentials. This can lead to further compromise of the entire Citrix infrastructure, including lateral movement to other systems. The CVSS score of 7.5 highlights the high severity due to the lack of authentication required and the potential for data breaches.

Get started to protecting your digital assets