CVE-2021-42850
Summary
| CVE | CVE-2021-42850 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-18 16:15:00 UTC |
| Updated | 2022-05-26 17:07:00 UTC |
| Description | A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lenovo | A1 | - | All | All | All |
| Operating System | Lenovo | A1 Firmware | All | All | All | All |
| Hardware | Lenovo | T1 | - | All | All | All |
| Operating System | Lenovo | T1 Firmware | All | All | All | All |
| Hardware | Lenovo | T2 | - | All | All | All |
| Hardware | Lenovo | T2pro | - | All | All | All |
| Operating System | Lenovo | T2pro Firmware | All | All | All | All |
| Operating System | Lenovo | T2 Firmware | All | All | All | All |
| Hardware | Lenovo | X1 | - | All | All | All |
| Operating System | Lenovo | X1 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 联想中国(Lenovo China)联想知识库 | CONFIRM | iknow.lenovo.com.cn | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Lenovo thanks Kais and KT of 360 Vulcan Team for reporting this issue.
There are currently no legacy QID mappings associated with this CVE.