Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-45085— When compute hosts are disabled and reenabled, they immediately transition to "ON", not "INIT"

Quick assessment

Affected
SoftIron HyperCloud
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SoftIron HyperCloud是SoftIron公司的一款智能云架构。 SoftIron HyperCloud 2.0.0至2.0.3之前版本存在安全漏洞,该漏洞源于计算节点会在没有正确初始化的情况下进行联机,导致工作负载被部署到错误状态。

CVSS 3.2 · Low EPSS 0.21% · P11

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-45085

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
When compute hosts are disabled and reenabled, they immediately transition to "ON", not "INIT"
Source: CVE Program / CVE List V5
Vulnerability Description
An issue exists in SoftIron HyperCloud where compute nodes may come online immediately without following the correct initialization process.  In this instance, workloads may be scheduled on these nodes and deploy to a failed or erroneous state, which impacts the availability of these workloads that may be deployed during this time window. This issue impacts HyperCloud versions from 2.0.0 to before 2.0.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1419
Source: CVE Program / CVE List V5
Vulnerability Title
SoftIron HyperCloud 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SoftIron HyperCloud是SoftIron公司的一款智能云架构。 SoftIron HyperCloud 2.0.0至2.0.3之前版本存在安全漏洞,该漏洞源于计算节点会在没有正确初始化的情况下进行联机,导致工作负载被部署到错误状态。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
SoftIron HyperCloud 2.0.0 ~ 2.0.3 -

II. Public POCs for CVE-2023-45085

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-45085

请登录查看更多情报信息。

Other References for CVE-2023-45085 (1)

Same Patch Batch · SoftIron · 2023-12-05 · 3 CVEs total

CVE-2023-45084 7.0 HIGH Media caddy removal and reinsertion without reboot may cause data loss
CVE-2023-45083 4.2 MEDIUM HyperCloud: "admin" and "serveradmin" users can be deleted

IV. Related Vulnerabilities

V. Comments for CVE-2023-45085

No comments yet


Leave a comment