Full Report
Progress security advisory (AV26-736)
Analysis Summary
# Vulnerability: Progress ShareFile Storage Zones Controller Improper Access Control
## CVE Details
- **CVE ID:** CVE-2024-6286
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-284 (Improper Access Control)
## Affected Systems
- **Products:** Progress ShareFile Storage Zones Controller
- **Versions:**
- Version 5.x prior to 5.12.4
- Version 6.x prior to 6.0.1
- **Configurations:** Systems hosting customer-managed storage zones.
## Vulnerability Description
A critical improper access control vulnerability exists in the Progress ShareFile Storage Zones Controller. The flaw allows an unauthenticated attacker to bypass security restrictions and gain unauthorized access to the controller. This is caused by insufficient validation of access tokens or requests, potentially allowing the attacker to compromise the integrity and confidentiality of the data stored within the managed zones.
## Exploitation
- **Status:** Not currently reported as exploited in the wild (as of advisory date); however, the severity suggests high interest for threat actors.
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Full access to files and data)
- **Integrity:** High (Ability to modify or delete files)
- **Availability:** High (Potential to disrupt service or delete critical data)
## Remediation
### Patches
Progress has released the following versions to address these vulnerabilities. Users should upgrade immediately:
- **ShareFile Storage Zones Controller v5.12.4**
- **ShareFile Storage Zones Controller v6.0.1**
### Workarounds
There are no official workarounds that provide full mitigation. Immediate patching is the recommended course of action. Blocking access to the controller from the public internet (if not required) can reduce the attack surface.
## Detection
- **Indicators of Compromise:** Monitor web server logs for unusual requests or unauthorized access attempts to the Storage Zones Controller endpoints.
- **Detection methods and tools:** Verify the installed version of the Storage Zones Controller via the configuration console or the executable file metadata to ensure it meets the minimum patched version requirements.
## References
- **Progress Trust Center:** hxxps[://]www[.]progress[.]com/trust-center
- **Cyber Centre Advisory:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/progress-security-advisory-av26-736
- **ShareFile Support:** hxxps[://]support[.]sharefile[.]com/s/article/ShareFile-Storage-Zones-Controller-Security-Update-July-2024