First published: Fri Apr 08 2016(Updated: )
The management interface in LenovoEMC EZ Media & Backup (hm3), ix2/ix2-dl, ix4-300d, px12-400r/450r, px6-300d, px2-300d, px4-300r, px4-400d, px4-400r, and px4-300d NAS devices with firmware before 4.1.204.33661 allows remote attackers to obtain sensitive device information via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo EMC Firmware | =4.1.204.33661 | |
Lenovo EMC EZ Media & Backup (hm3) | ||
Lenovo EMC ix2/ix2-dl | ||
Lenovo EMC ix4-300d | ||
Lenovo EMC px12-400r/450r | ||
Lenovo px2-300d | ||
Lenovo px4-300d firmware | ||
Lenovo PX4-300R | ||
Lenovo PX4-400D | ||
Lenovo px4-400r | ||
Lenovo PX6-300D Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8108 is classified as a high severity vulnerability due to its potential to expose sensitive device information to remote attackers.
To mitigate CVE-2015-8108, upgrade the firmware of affected LenovoEMC NAS devices to version 4.1.204.33661 or later.
CVE-2015-8108 affects various LenovoEMC NAS devices, including ix2, ix4-300d, and px12-400r among others, running firmware versions prior to 4.1.204.33661.
CVE-2015-8108 allows remote attackers to obtain sensitive device information, which could lead to further exploitation.
There are no official workarounds for CVE-2015-8108 other than applying the firmware update to eliminate the vulnerability.