PT-2024-17909 · Softiron · Softiron Hypercloud
Published
2024-12-30
·
Updated
2024-12-30
·
CVE-2024-13058
CVSS v4.0
4.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:L/S:N/AU:Y/R:U/V:D/RE:M/U:Green |
Name of the Vulnerable Software and Affected Versions
SoftIron HyperCloud versions 2.3.0 through 2.4.x
Description
An issue exists where authenticated, but non-admin users can create data pools, potentially impacting the performance and availability of the backend software-defined storage subsystem.
Recommendations
For versions 2.3.0 through 2.4.x, consider restricting access to data pool creation functionality to only admin users until a patch is available.
As a temporary workaround, consider disabling data pool creation for non-admin users to minimize the risk of exploitation.
Fix
Improper Authorization
Resource Exhaustion
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Softiron Hypercloud