CVE-2021-42852

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
18/05/2022
Last modified:
26/05/2022

Description

A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lenovo:a1_firmware:*:*:*:*:*:*:*:* 5.3.6.a1 (excluding)
cpe:2.3:h:lenovo:a1:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:t1_firmware:*:*:*:*:*:*:*:* 5.3.6.t1 (excluding)
cpe:2.3:h:lenovo:t1:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:x1_firmware:*:*:*:*:*:*:*:* 5.3.8.x1 (excluding)
cpe:2.3:h:lenovo:x1:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:t2_firmware:*:*:*:*:*:*:*:* 5.3.8.t2 (excluding)
cpe:2.3:h:lenovo:t2:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:t2pro_firmware:*:*:*:*:*:*:*:* 5.3.7.t2-pro (excluding)
cpe:2.3:h:lenovo:t2pro:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools