SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-45084

An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause the system to recognize the caddy as new media and wipe all data on the drives due to a missing synchronization flaw, which impacts…

MEDIUM 6.1EPSS 0.22%

Does this matter?

Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.

Description

An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause the system to recognize the caddy as new media and wipe all data on the drives due to a missing synchronization flaw, which impacts data availability and integrity. This issue only impacts SoftIron HyperCloud "density" storage nodes running HyperCloud software versions 1.0 to before 2.0.3.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS
0.22% probability · 13th percentile
CISA KEV
Not listed
Weakness
CWE-820, CWE-662
Affected
softiron/hypercloud
Source
0a72a055-908d-47f5-a16a-1f09049c16c6

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.