{"api_version":"1","generated_at":"2026-07-23T12:10:37+00:00","cve":"CVE-2021-3616","urls":{"html":"https://cve.report/CVE-2021-3616","api":"https://cve.report/api/cve/CVE-2021-3616.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-3616","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-3616"},"summary":{"title":"CVE-2021-3616","description":"A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerability is the same as CNVD-2020-68651.","state":"PUBLIC","assigner":"psirt@lenovo.com","published_at":"2021-08-17 17:15:00","updated_at":"2021-08-30 18:31:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://www.cnvd.org.cn/flaw/show/CNVD-2020-68651","name":"https://www.cnvd.org.cn/flaw/show/CNVD-2020-68651","refsource":"MISC","tags":[],"title":"","mime":"text/html","httpstatus":"521","archivestatus":"404"},{"url":"https://iknow.lenovo.com.cn/detail/dc_198417.html","name":"https://iknow.lenovo.com.cn/detail/dc_198417.html","refsource":"MISC","tags":[],"title":"联想中国(Lenovo China)联想知识库","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-3616","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3616","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Lenovo thanks Charles Jiang and Xingcan Chen from Lenovo Global Security Lab for reporting these issues.","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"3616","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"lenovo","cpe5":"smart_camera_c2e","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"3616","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"lenovo","cpe5":"smart_camera_c2e_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"3616","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"lenovo","cpe5":"smart_camera_x3","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"3616","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"lenovo","cpe5":"smart_camera_x3_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"3616","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"lenovo","cpe5":"smart_camera_x5","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"3616","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"lenovo","cpe5":"smart_camera_x5_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@lenovo.com","ID":"CVE-2021-3616","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Smart Camera X3, X5, and C2E firmware","version":{"version_data":[{"version_affected":"<","version_value":"01.03.29.16"}]}}]},"vendor_name":"Lenovo"}]}},"credit":[{"lang":"eng","value":" Lenovo thanks Charles Jiang and Xingcan Chen from Lenovo Global Security Lab for reporting these issues."}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerability is the same as CNVD-2020-68651."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.4,"baseSeverity":"CRITICAL","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-285 Improper Authorization"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://iknow.lenovo.com.cn/detail/dc_198417.html","name":"https://iknow.lenovo.com.cn/detail/dc_198417.html"},{"refsource":"MISC","url":"https://www.cnvd.org.cn/flaw/show/CNVD-2020-68651","name":"https://www.cnvd.org.cn/flaw/show/CNVD-2020-68651"}]},"solution":[{"lang":"eng","value":"Update to Lenovo Smart Camera X3, X5, and C2E firmware version 01.03.29.16 or later."}],"source":{"advisory":"LEN-49262","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-08-17 17:15:00","lastModifiedDate":"2021-08-30 18:31:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:lenovo:smart_camera_c2e_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"01.03.29.16","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:lenovo:smart_camera_c2e:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]},{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:lenovo:smart_camera_x3_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"01.03.29.16","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:lenovo:smart_camera_x3:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]},{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:lenovo:smart_camera_x5_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"01.03.29.16","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:lenovo:smart_camera_x5:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"3616","Ordinal":"210965","Title":"CVE-2021-3616","CVE":"CVE-2021-3616","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"3616","Ordinal":"1","NoteData":"A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerability is the same as CNVD-2020-68651.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"3616","Ordinal":"2","NoteData":"2021-08-17","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"3616","Ordinal":"3","NoteData":"2021-08-17","Type":"Other","Title":"Modified"}]}}}