PT-2024-17909 · Softiron · Softiron Hypercloud

CVE-2024-13058

·

Published

2024-12-30

·

Updated

2024-12-30

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:L/S:N/AU:Y/R:U/V:D/RE:M/U:Green
Name of the Vulnerable Software and Affected Versions SoftIron HyperCloud versions 2.3.0 through 2.4.x
Description An issue exists where authenticated, but non-admin users can create data pools, potentially impacting the performance and availability of the backend software-defined storage subsystem.
Recommendations For versions 2.3.0 through 2.4.x, consider restricting access to data pool creation functionality to only admin users until a patch is available. As a temporary workaround, consider disabling data pool creation for non-admin users to minimize the risk of exploitation.

Fix

Improper Authorization

Resource Exhaustion

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13058

Affected Products

Softiron Hypercloud