CVE-2021-42850
Last modified
CVE-2021-42850 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | A1 Firmware | < 5.3.6.a1 |
| Lenovo | T1 Firmware | < 5.3.6.t1 |
| Lenovo | X1 Firmware | < 5.3.8.x1 |
| Lenovo | T2 Firmware | < 5.3.8.t2 |
| Lenovo | T2pro Firmware | < 5.3.7.t2-pro |
References
- https://iknow.lenovo.com.cn/detail/dc_200017.htmlVendor Advisory
- https://iknow.lenovo.com.cn/detail/dc_200017.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-42850?
How severe is CVE-2021-42850?
How do I fix CVE-2021-42850?
Are you affected by CVE-2021-42850?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
