logo

Bugs in the Cloud: How One Vulnerability Exposed ‘Offline’ Devices to a Security Risk

ID: e9b60625-1a61-5c01-9128-a82901bc142a

STIX ID: report--e9b60625-1a61-5c01-9128-a82901bc142a

Feed Name: Claroty Team82

Threat Score
55/100

Date Published: 2023-08-23

Date Updated: 2026-04-17

Author: Sharon Brizinov; Amir Preminger

...
...

**Executive Summary:** Claroty Team82 discovered and disclosed a directory traversal vulnerability (CVE-2021-22685) in Cassia Networks' IoT Access Controller v1.4 that allowed unauthenticated attackers to read arbitrary files from the server container—potentially exposing configuration files, application source code, logs, and hashed passwords; dozens of cloud instances were found vulnerable before patches and Cassia released version 2.0 to remediate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.