Vulnerability Name:

CVE-2015-8108 (CCN-112541)

Assigned:2015-11-11
Published:2016-03-10
Updated:2016-04-14
Summary:The management interface in LenovoEMC EZ Media & Backup (hm3), ix2/ix2-dl, ix4-300d, px12-400r/450r, px6-300d, px2-300d, px4-300r, px4-400d, px4-400r, and px4-300d NAS devices with firmware before 4.1.204.33661 allows remote attackers to obtain sensitive device information via unspecified vectors.
CVSS v3 Severity:5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-254
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2015-8108

Source: XF
Type: UNKNOWN
lenovoemc-cve20158108-info-disc(112541)

Source: CCN
Type: Lenovo Security Advisory: LEN-3846
Information about LenovoEMC devices may be disclosed if the device has an Internet-accessible management interface

Source: CONFIRM
Type: Vendor Advisory
https://support.lenovo.com/us/en/product_security/len_3846

Vulnerable Configuration:Configuration 1:
  • cpe:/a:lenovo:emc_firmware:4.1.204.33661:*:*:*:*:*:*:*
  • AND
  • cpe:/h:lenovo:emc_ez_media_&_backup_(hm3):-:*:*:*:*:*:*:*
  • OR cpe:/h:lenovo:emc_ix2/ix2-dl:-:*:*:*:*:*:*:*
  • OR cpe:/h:lenovo:emc_ix4-300d_(inc_dl):-:*:*:*:*:*:*:*
  • OR cpe:/h:lenovo:emc_px12-400r/450r:-:*:*:*:*:*:*:*
  • OR cpe:/h:lenovo:emc_px2-300d:-:*:*:*:*:*:*:*
  • OR cpe:/h:lenovo:emc_px4-300d:-:*:*:*:*:*:*:*
  • OR cpe:/h:lenovo:emc_px4-300r:-:*:*:*:*:*:*:*
  • OR cpe:/h:lenovo:emc_px4-400d:-:*:*:*:*:*:*:*
  • OR cpe:/h:lenovo:emc_px4-400r:-:*:*:*:*:*:*:*
  • OR cpe:/h:lenovo:emc_px6-300d:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    lenovo emc firmware 4.1.204.33661
    lenovo emc ez media & backup (hm3) -
    lenovo emc ix2/ix2-dl -
    lenovo emc ix4-300d (inc dl) -
    lenovo emc px12-400r/450r -
    lenovo emc px2-300d -
    lenovo emc px4-300d -
    lenovo emc px4-300r -
    lenovo emc px4-400d -
    lenovo emc px4-400r -
    lenovo emc px6-300d -