Aller au contenu

Fiche vulnérabilité

CVE-2021-42850 : faille élevée Lenovo Personal Cloud Storage A1 (CVSS 8.8)

Description

A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
18 mai 2022
Dernière mise à jour
4 août 2024

Produits concernés

  • Lenovo Personal Cloud Storage A1
  • Lenovo Personal Cloud Storage T1
  • Lenovo Personal Cloud Storage X1
  • Lenovo Personal Cloud Storage T2
  • Lenovo Personal Cloud Storage T2Pro

Correctif et mesures

Update to the Lenovo Personal Cloud Storage device firmware listed in the product table in LEN-73439.

Références

Rechercher une autre vulnérabilité dans la base CVE