Bugs in the Cloud: How One Vulnerability Exposed ‘Offline’ Devices to a Security Risk
ID: e9b60625-1a61-5c01-9128-a82901bc142a
STIX ID: report--e9b60625-1a61-5c01-9128-a82901bc142a
Feed Name: Claroty Team82
Threat Score
**Executive Summary:** Claroty Team82 discovered and disclosed a directory traversal vulnerability (CVE-2021-22685) in Cassia Networks' IoT Access Controller v1.4 that allowed unauthenticated attackers to read arbitrary files from the server container—potentially exposing configuration files, application source code, logs, and hashed passwords; dozens of cloud instances were found vulnerable before patches and Cassia released version 2.0 to remediate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
