CVE-2024-13058: Softiron Hypercloud

Medium severity, CVSS 4.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue exists in SoftIron HyperCloud where authenticated, but non-admin users can create data pools, which could potentially impact the performance and availability of the backend software-defined storage subsystem. This issue only impacts SoftIron HyperCloud and related software products (such as VM Squared) software versions 2.3.0 to before 2.5.0.

Affected products

  • Softiron Hypercloud: from 2.3.0, before 2.5.0 (fixed in 2.5.0)

Published 2024-12-30. Last modified 2026-06-17.