CVE-2025-10650

⚪ Do wiadomości

Błąd w SoftIron HyperCloud umożliwia nieautoryzowaną eskalację uprawnień do admina przez SSH.

CVSS
0.0
EPSS
0.1%
Exploit
none
Vendor
Opis źródłowy (NVD)

SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH. Affects non-production debug and internal development builds created between versions 2.5.0 and 2.6.3.  No generally available (GA) or customer-released production builds were affected.  There is no evidence that this issue was exposed in customer environments or production deployments.

privilege-escalation Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS0.0
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.1%
Opublikowano (NVD)2025-09-18 19:15:37 UTC
Ostatnia modyfikacja (NVD)2026-09-30 23:10:00 UTC
Referencje