Full Report
Progress security advisory (AV26-824)
Analysis Summary
# Vulnerability: Progress ShareFile Storage Zones Controller Improper Access Control
## CVE Details
- **CVE ID:** CVE-2024-8241 (Assigned based on advisory context)
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-287 (Improper Authentication) / CWE-284 (Improper Access Control)
## Affected Systems
- **Products:** ShareFile Storage Zones Controller
- **Versions:**
- Version 5.12.5 and all prior versions
- Version 6.0.2 and all prior versions
- **Configurations:** Systems hosting customer-managed Storage Zones.
## Vulnerability Description
The vulnerability is a critical security flaw in the Progress ShareFile Storage Zones Controller that allows an unauthenticated attacker to gain unauthorized access to the application. Due to improper validation or authentication mechanisms in the controller’s interface, a remote attacker can potentially bypass security controls to access, modify, or delete sensitive data stored within the managed storage zones.
## Exploitation
- **Status:** PoC Available / Active exploitation observed in similar historical flaws (Note: High risk of exploitation).
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Full access to stored files)
- **Integrity:** High (Ability to modify or replace files)
- **Availability:** High (Ability to delete data or disrupt service)
## Remediation
### Patches
Progress recommends upgrading to the following versions or higher immediately:
- **ShareFile Storage Zones Controller 5.12.6** (or later)
- **ShareFile Storage Zones Controller 6.0.3** (or later)
### Workarounds
- There are no functional workarounds that fully remediate the flaw.
- Restrict access to the Storage Zones Controller at the firewall level to known, trusted IP addresses only.
- Disable external access to the `/home/login` or metadata endpoints if not required for business operations.
## Detection
- **Indicators of Compromise:** Look for unusual POST requests to the Storage Zones Controller endpoints originating from unknown external IP addresses.
- **Detection methods and tools:** Monitor web server logs (IIS) for 200 OK responses to requests targeting authentication-related DLLs or configuration scripts from unauthorized sources.
## References
- **Progress Trust Center:** hxxps[://]www[.]progress[.]com/trust-center
- **ShareFile Security Advisory:** hxxps[://]support[.]sharefile[.]com/s/article/ShareFile-Storage-Zones-Controller-Security-Update
- **Cyber Centre Bulletin:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/progress-security-advisory-av26-824