Impact
A container in Microsoft Azure Blob Storage that holds Gardyn device logs is publicly listable without requiring authentication. This misconfigured permission – classified as CWE‑497 – allows a remote attacker to enumerate and download any log file stored in the container. The exposed logs may contain device configuration, state, and user activity information, thereby compromising confidentiality of the system.
Affected Systems
The flaw affects Gardyn products that use Azure Blob Storage for logging, including the Gardyn Cloud API, Gardyn Home Firmware, and Gardyn Studio Firmware. Specific affected product versions are not listed, so any deployment that has not yet applied the vendor’s updated infrastructure remains at risk until a fix is installed.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate risk. With the EPSS score of < 1% and the vulnerability currently not listed in CISA KEV, the likelihood of exploitation is low at present. Nevertheless, the attack vector is remote – an attacker can exploit the flaw from any internet‑connected location without credentials, making the vulnerability straightforward to leverage until the vendor releases and users apply the update.
OpenCVE Enrichment