Vulnerability Description
The management interface in LenovoEMC EZ Media & Backup (hm3), ix2/ix2-dl, ix4-300d, px12-400r/450r, px6-300d, px2-300d, px4-300r, px4-400d, px4-400r, and px4-300d NAS devices with firmware before 4.1.204.33661 allows remote attackers to obtain sensitive device information via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Emc Firmware | 4.1.204.33661 |
| Lenovo | Emc Ez Media \& Backup \(Hm3\) | - |
| Lenovo | Emc Ix2\/Ix2-Dl | - |
| Lenovo | Emc Ix4-300D \(Inc Dl\) | - |
| Lenovo | Emc Px12-400R\/450R | - |
| Lenovo | Emc Px2-300D | - |
| Lenovo | Emc Px4-300D | - |
| Lenovo | Emc Px4-300R | - |
| Lenovo | Emc Px4-400D | - |
| Lenovo | Emc Px4-400R | - |
| Lenovo | Emc Px6-300D | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/len_3846Vendor Advisory
- https://support.lenovo.com/us/en/product_security/len_3846Vendor Advisory
FAQ
What is CVE-2015-8108?
CVE-2015-8108 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The management interface in LenovoEMC EZ Media & Backup (hm3), ix2/ix2-dl, ix4-300d, px12-400r/450r, px6-300d, px2-300d, px4-300r, px4-400d, px4-400r, and px4-300d NAS devices with firmware before 4.1...
How severe is CVE-2015-8108?
CVE-2015-8108 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-8108?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Emc Firmware, Lenovo Emc Ez Media \& Backup \(Hm3\), Lenovo Emc Ix2\/Ix2-Dl, Lenovo Emc Ix4-300D \(Inc Dl\), Lenovo Emc Px12-400R\/450R.