Description
An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause the system to recognize the caddy as new media and wipe all data on the drives due to a missing synchronization flaw, which impacts data availability and integrity. This issue only impacts SoftIron HyperCloud "density" storage nodes running HyperCloud software versions 1.0 to before 2.0.3.
References (1)
Core 1
Core References
Release Notes
https://advisories.softiron.cloud
Scores
CVSS v3
7.0
EPSS
0.0022
EPSS Percentile
12.9%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-820
CWE-662
Status
published
Products (1)
softiron/hypercloud
1.0 - 2.0.3
Published
Dec 05, 2023
Tracked Since
Feb 18, 2026