Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Control Sphere
Vulnerability Description
The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device log file available in the blob storage container.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
将系统数据暴露到未授权控制的范围
Vulnerability Title
Gardyn Home Firmware 信息泄露漏洞
Vulnerability Description
Gardyn Home Firmware是美国Gardyn公司的一个智能室内水培种植设备的固件。 Gardyn Home Firmware master.627之前版本、Gardyn Studio Firmware master.627之前版本和Gardyn Cloud API 2.12.2026之前版本存在信息泄露漏洞,该漏洞源于Azure Blob Storage容器未经验证即可公开列出,可能导致恶意用户访问设备日志文件。
CVSS Information
N/A
Vulnerability Type
N/A