CVE-2023-45083: HyperCloud: "admin" and "serveradmin" users can be deleted
Published Dec 5, 2023
·Updated
An Improper Privilege Management vulnerability exists in HyperCloud that will impact the ability for a user to authenticate against the management plane.
An authenticated admin-level user may be able to delete the "admin" or "serveradmin" users, which prevents authentication from subsequently succeeding.
This issue affects HyperCloud versions 1.0 to any release before 2.1.
Affected Software
1 affected component
SoftIron HyperCloud>=1.0<2.1.0
Event History
Dec 5, 2023
CVE Published
04:15 PM
Data Sourced
04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the impact of CVE-2023-45083?
An authenticated admin-level user may be able to delete the 'admin' or 'serveradmin' users, impacting authentication against the management plane in HyperCloud.
2
How can the CVE-2023-45083 vulnerability be exploited?
The vulnerability can be exploited by an admin-level user deleting the 'admin' or 'serveradmin' users in HyperCloud.
3
Is CVE-2023-45083 a critical vulnerability?
The severity of CVE-2023-45083 is rated as medium with a CVSS score of 4.2.