CVE-2025-10650: Improper SSH Key Handling in Internal Debug Builds May Grant Cluster-Level Access to Non-Administrative Users
SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH. Affects non-production debug and internal development builds created between versions 2.5.0 and 2.6.3. No generally available (GA) or customer-released production builds were affected. There is no evidence that this issue was exposed in customer environments or production deployments.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10650?
CVE-2025-10650 is classified as a high-severity vulnerability due to the potential for unauthorized privilege escalation.
How do I fix CVE-2025-10650?
To fix CVE-2025-10650, update SoftIron HyperCloud to version 2.6.4 or later, which addresses this vulnerability.
What is the impact of CVE-2025-10650 on my system?
The impact of CVE-2025-10650 allows unauthorized users to gain administrator-level access via SSH, compromising system security.
What versions are affected by CVE-2025-10650?
CVE-2025-10650 affects SoftIron HyperCloud versions 2.5.0 to 2.6.3.
How can unauthorized access occur with CVE-2025-10650?
Unauthorized access can occur in CVE-2025-10650 due to improper handling of user SSH keys, allowing malicious users to escalate privileges.