Impact
The vulnerability is that a container in Microsoft Azure Blob Storage used for Gardyn device logs is publicly listable without authentication. This is an example of CWE-497: Misconfigured Permissions. Because no access controls are enforced, a malicious actor can enumerate and download any log file that is stored in the container. This leakage of log data can expose configuration, device state, or user activity information, thereby compromising confidentiality.
Affected Systems
The flaw affects Gardyn products that use Azure Blob Storage for logging, including the Gardyn Cloud API, Gardyn Home Firmware, and Gardyn Studio Firmware. Any current deployment of these products that has not applied the updated infrastructure is susceptible until the vendor releases a fix.
Risk and Exploitability
With a CVSS score of 6.9 the risk is moderate. The likely attack vector is remote internet access to the publicly reachable Azure Blob Storage container, requiring no authentication and allowing straightforward exploitation. The EPSS score of < 1% and absence from the CISA KEV catalog suggest a low probability of exploitation at present, but the vulnerability remains exploitable from any remote location until the vendor’s update is deployed.
OpenCVE Enrichment