PT-2024-17909 · Softiron · Softiron Hypercloud

Published

2024-12-30

·

Updated

2024-12-30

·

CVE-2024-13058

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:L/S:N/AU:Y/R:U/V:D/RE:M/U:Green
Name of the Vulnerable Software and Affected Versions SoftIron HyperCloud versions 2.3.0 through 2.4.x
Description An issue exists where authenticated, but non-admin users can create data pools, potentially impacting the performance and availability of the backend software-defined storage subsystem.
Recommendations For versions 2.3.0 through 2.4.x, consider restricting access to data pool creation functionality to only admin users until a patch is available. As a temporary workaround, consider disabling data pool creation for non-admin users to minimize the risk of exploitation.

Fix

Improper Authorization

Resource Exhaustion

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2024-13058

Affected Products

Softiron Hypercloud