Vulnerability Details CVE-2015-9256
Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not have ACLs by default.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.7%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2015-9256
-
-
-
cpe:2.3:h:datto:alto_imaged:-
-
cpe:2.3:h:datto:alto_xl:-
-
cpe:2.3:h:datto:siris_2:-
-
cpe:2.3:h:datto:siris_3:-
-
cpe:2.3:h:datto:siris_3_x_all-flash:-
-
cpe:2.3:h:datto:siris_virtual:-
-
cpe:2.3:o:datto:alto_2_firmware:-
-
cpe:2.3:o:datto:alto_3_firmware:-
-
cpe:2.3:o:datto:alto_imaged_firmware:-
-
cpe:2.3:o:datto:alto_xl_firmware:-
-
cpe:2.3:o:datto:siris_2_firmware:-
-
cpe:2.3:o:datto:siris_3_firmware:-
-
cpe:2.3:o:datto:siris_3_x_all-flash_firmware:-
-
cpe:2.3:o:datto:siris_virtual_firmware:-