ID

VAR-201506-0332


CVE

CVE-2014-8391


TITLE

Sendio ESP Information Disclosure Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2015-03578 // CNNVD: CNNVD-201506-028

DESCRIPTION

The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive information from other users' sessions via a large number of requests. Sendio ESP (Email Security Platform) is a network device that provides anti-spam and anti-virus solutions for enterprises in Sendio, USA. A security vulnerability exists in the web interface of Sendio ESP prior to 7.2.4. The program failed to process the session correctly. Sendio ESP is prone to multiple information-disclosure vulnerabilities

Trust: 2.52

sources: NVD: CVE-2014-8391 // JVNDB: JVNDB-2014-008068 // CNVD: CNVD-2015-03578 // BID: 74786 // VULMON: CVE-2014-8391

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-03578

AFFECTED PRODUCTS

vendor:sendiomodel:sendioscope:lteversion:7.2.3

Trust: 1.0

vendor:sendiomodel:sendioscope:ltversion:7.2.4

Trust: 0.8

vendor:sendiomodel:espscope:ltversion:7.2.4

Trust: 0.6

vendor:sendiomodel:sendioscope:eqversion:7.2.3

Trust: 0.6

vendor:sendiomodel:espscope:eqversion:0

Trust: 0.3

vendor:sendiomodel:sendioscope:eqversion:6(14.1120.0)

Trust: 0.3

vendor:sendiomodel:sendioscope:neversion:7.2.4

Trust: 0.3

sources: CNVD: CNVD-2015-03578 // BID: 74786 // JVNDB: JVNDB-2014-008068 // CNNVD: CNNVD-201506-028 // NVD: CVE-2014-8391

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-8391
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-8391
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-03578
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201506-028
value: MEDIUM

Trust: 0.6

VULMON: CVE-2014-8391
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-8391
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

NVD: CVE-2014-8391
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2015-03578
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2015-03578 // VULMON: CVE-2014-8391 // JVNDB: JVNDB-2014-008068 // CNNVD: CNNVD-201506-028 // NVD: CVE-2014-8391

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.8

sources: JVNDB: JVNDB-2014-008068 // NVD: CVE-2014-8391

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201506-028

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201506-028

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-008068

EXPLOIT AVAILABILITY

sources: VULMON: CVE-2014-8391

PATCH

title:21-May-2015 Version 7.2.4 Improvements, Security and Bug Fix Updatesurl:http://www.sendio.com/software-release-history/

Trust: 0.8

title:Sendio ESP Information Disclosure Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/59284

Trust: 0.6

title:martingalloarurl:https://github.com/martingalloar/martingalloar

Trust: 0.1

title:publicationsurl:https://github.com/martingalloar/publications

Trust: 0.1

sources: CNVD: CNVD-2015-03578 // VULMON: CVE-2014-8391 // JVNDB: JVNDB-2014-008068

EXTERNAL IDS

db:NVDid:CVE-2014-8391

Trust: 3.4

db:PACKETSTORMid:132022

Trust: 2.5

db:EXPLOIT-DBid:37114

Trust: 2.3

db:JVNDBid:JVNDB-2014-008068

Trust: 0.8

db:EXPLOITDBid:37114

Trust: 0.6

db:CNVDid:CNVD-2015-03578

Trust: 0.6

db:CNNVDid:CNNVD-201506-028

Trust: 0.6

db:BIDid:74786

Trust: 0.4

db:VULMONid:CVE-2014-8391

Trust: 0.1

sources: CNVD: CNVD-2015-03578 // VULMON: CVE-2014-8391 // BID: 74786 // JVNDB: JVNDB-2014-008068 // CNNVD: CNNVD-201506-028 // NVD: CVE-2014-8391

REFERENCES

url:http://packetstormsecurity.com/files/132022/sendio-esp-information-disclosure.html

Trust: 2.5

url:https://www.exploit-db.com/exploits/37114/

Trust: 2.4

url:http://www.sendio.com/software-release-history/

Trust: 1.7

url:http://seclists.org/fulldisclosure/2015/may/95

Trust: 1.7

url:http://www.securityfocus.com/archive/1/535592/100/0/threaded

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-8391

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-8391

Trust: 0.8

url:http://www.securityfocus.com/archive/1/archive/1/535592/100/0/threaded

Trust: 0.6

url:http://www.sendio.com/

Trust: 0.3

url:http://www.coresecurity.com/advisories/sendio-esp-information-disclosure-vulnerability

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/200.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://www.securityfocus.com/bid/74786

Trust: 0.1

url:https://github.com/martingalloar/martingalloar

Trust: 0.1

sources: CNVD: CNVD-2015-03578 // VULMON: CVE-2014-8391 // BID: 74786 // JVNDB: JVNDB-2014-008068 // CNNVD: CNNVD-201506-028 // NVD: CVE-2014-8391

CREDITS

Martin Gallo from Core Security's Consulting Services Team

Trust: 0.3

sources: BID: 74786

SOURCES

db:CNVDid:CNVD-2015-03578
db:VULMONid:CVE-2014-8391
db:BIDid:74786
db:JVNDBid:JVNDB-2014-008068
db:CNNVDid:CNNVD-201506-028
db:NVDid:CVE-2014-8391

LAST UPDATE DATE

2025-04-13T23:09:49.654000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-03578date:2015-06-04T00:00:00
db:VULMONid:CVE-2014-8391date:2018-10-09T00:00:00
db:BIDid:74786date:2015-05-22T00:00:00
db:JVNDBid:JVNDB-2014-008068date:2015-06-04T00:00:00
db:CNNVDid:CNNVD-201506-028date:2015-06-05T00:00:00
db:NVDid:CVE-2014-8391date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-03578date:2015-06-04T00:00:00
db:VULMONid:CVE-2014-8391date:2015-06-02T00:00:00
db:BIDid:74786date:2015-05-22T00:00:00
db:JVNDBid:JVNDB-2014-008068date:2015-06-04T00:00:00
db:CNNVDid:CNNVD-201506-028date:2015-06-03T00:00:00
db:NVDid:CVE-2014-8391date:2015-06-02T14:59:01.833