Security Advisory

CVE-2019-7218

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-05-13 18:19:19
Last updated 2024-08-04 20:46:44
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like google authenticator) is able to bypass the first authentication phase (username/password mechanism) and log-in using username/otp combination only (phase 2 of 2FA).