SoftIron

First CVE: Dec 5, 2023Active for: 3 years
6
CVEs Published
More CVEs Published than 18% of tracked CNAs
1.5
Avg CVEs / Year
More Avg CVEs / Year than 8% of tracked CNAs
4.4
Avg CVSS Score
Higher Avg CVSS Score than 2% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by SoftIron as a CNA, 100.0% affect products that SoftIron develops as a vendor.

100.0%
Self-reported: 6Third-party: 0

Of all the CVEs published that affect products developed by SoftIron, 100.0% are self-published by SoftIron as a CNA.

100.0%
Self-published: 6Published by other CNAs: 0

Trends Over Time

The number and severity of CVEs published by SoftIron over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 5, 2023
2 years ago
Most Recent CVE
Feb 20, 2026
154 days ago

Top CVEs

All CVEs published by SoftIron as a CNA, regardless of affected vendor or product.

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
HyperCloud versions 2.3.5 through 2.6.8 improperly allowed refresh tokens to be used directly for resource access and failed to invalidate previously issued access tokens when a re
Feb 20, 20266.221NONO
An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause the system to recognize the caddy as new media and wipe all
Dec 5, 20236.120NONO
An issue exists in SoftIron HyperCloud where authenticated, but non-admin users can create data pools, which could potentially impact the performance and availability of the backe
Dec 30, 20244.816NONO
SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escal
Sep 18, 20251.815NONO
An issue exists in SoftIron HyperCloud where compute nodes may come online immediately without following the correct initialization process.  In this instance, workloads may be sch
Dec 5, 20233.314NONO
An Improper Privilege Management vulnerability exists in HyperCloud that will impact the ability for a user to authenticate against the management plane. An authenticated admin-le
Dec 5, 20234.414NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA6 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMedium
Attack Vector
Local2 (33.3%)
Network3 (50.0%)
Unknown0 (0.0%)
Physical1 (16.7%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (66.7%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (66.7%)
High1 (16.7%)
None1 (16.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by SoftIron as a CNA.

Media Mentions

Media articles that mention a CVE ID published by SoftIron as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs