Citrix ShareFile through 19.1 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim?s otp physical token or virtual app (like google authenticator) is able to bypass the first authentication phase (username/password mechanism) and log-in using username/otp combination only (phase 2 of 2FA).

  • Published Date: Monday 13th of May 2019 03:29:01 PM
  • Modified Date: Tuesday 14th of May 2019 01:08:52 PM
    • Network Access Vector: The attacker does not require local network access or local access.
    • Authentication Vector: Authentication is not required to access and exploit the vulnerability.
    • Complexity Vector: One instance of complexity is required to access and exploit the vulnerability.
    • Availability Impact: There is no impact to the availability of the system.
    • Integrity Impact: Modification of some system files is posible.
    • Confidentiality Impact: There is none information disclosure.
    • CVSS Score: 4.3
    • Common Platform Enumeration (CPE) Dictionary
      • cpe:2.3:a:citrix:sharefile:19.1
    • Reference:

    Download Mageni's Vulnerability Scanning Platform.

    No credit card is required to download the Free Edition. Register now.