CVE-2015-9255

Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machines via a request to a Web Virtual Directory.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:datto:alto_3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:datto:alto_3:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:datto:alto_2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:datto:alto_2:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:datto:alto_xl_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:datto:alto_xl:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:datto:siris_3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:datto:siris_3:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:datto:siris_2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:datto:siris_2:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:datto:siris_3_x_all-flash_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:datto:siris_3_x_all-flash:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:datto:siris_virtual_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:datto:siris_virtual:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:datto:alto_imaged_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:datto:alto_imaged:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:40

Type Values Removed Values Added
References () http://www.information-paradox.net/2015/02/cve-2015-2081-multiple-vulnerabilities.html - Third Party Advisory () http://www.information-paradox.net/2015/02/cve-2015-2081-multiple-vulnerabilities.html - Third Party Advisory

Information

Published : 2018-02-20 06:29

Updated : 2024-11-21 02:40


NVD link : CVE-2015-9255

Mitre link : CVE-2015-9255

CVE.ORG link : CVE-2015-9255


JSON object : View

Products Affected

datto

  • alto_imaged_firmware
  • alto_2_firmware
  • siris_3_firmware
  • siris_2_firmware
  • alto_xl
  • alto_3
  • alto_3_firmware
  • siris_2
  • siris_virtual_firmware
  • siris_3_x_all-flash_firmware
  • alto_imaged
  • siris_3_x_all-flash
  • alto_xl_firmware
  • alto_2
  • siris_virtual
  • siris_3
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor