CVE-2021-42850
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.
Affected (5)
Products: Lenovo: A1 Firmware, T1 Firmware, X1 Firmware, T2 Firmware, T2pro Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.3.6.a1 |
| Running on/with | Platform Versions |
|---|---|
Lenovo A1 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.3.6.t1 |
| Running on/with | Platform Versions |
|---|---|
Lenovo T1 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.3.8.x1 |
| Running on/with | Platform Versions |
|---|---|
Lenovo X1 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.3.8.t2 |
| Running on/with | Platform Versions |
|---|---|
Lenovo T2 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.3.7.t2-pro |
| Running on/with | Platform Versions |
|---|---|
Lenovo T2pro | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.