SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-45083

An Improper Privilege Management vulnerability exists in HyperCloud that will impact the ability for a user to authenticate against the management plane.

MEDIUM 4.4EPSS 0.24%

Does this matter?

Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.

Description

An Improper Privilege Management vulnerability exists in HyperCloud that will impact the ability for a user to authenticate against the management plane. An authenticated admin-level user may be able to delete the "admin" or "serveradmin" users, which prevents authentication from subsequently succeeding. This issue affects HyperCloud versions 1.0 to any release before 2.1.

CVSS 3.1
4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
EPSS
0.24% probability · 15th percentile
CISA KEV
Not listed
Weakness
CWE-269
Affected
softiron/hypercloud
Source
0a72a055-908d-47f5-a16a-1f09049c16c6

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.