« Volver al listado

CVE-2021-42849

Estado: ModificadaMedia (6.8)—

A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-42849",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@lenovo.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@lenovo.com",
      "affectedData": [
        {
          "vendor": "Lenovo",
          "product": "Personal Cloud Storage A1",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.3.6.a1",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Lenovo",
          "product": "Personal Cloud Storage T1",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.3.6.t1",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Lenovo",
          "product": "Personal Cloud Storage X1",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.3.8.x1",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Lenovo",
          "product": "Personal Cloud Storage T2",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.3.8.t2",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Lenovo",
          "product": "Personal Cloud Storage T2Pro",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.3.7.t2-pro",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-05-18T16:15:08.247",
  "references": [
    {
      "url": "https://iknow.lenovo.com.cn/detail/dc_200017.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@lenovo.com"
    },
    {
      "url": "https://iknow.lenovo.com.cn/detail/dc_200017.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@lenovo.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access."
    },
    {
      "lang": "es",
      "value": "En algunos dispositivos Lenovo Personal Cloud Storage fue notificado una contraseña débil por defecto para el puerto serie que podría permitir el acceso no autorizado al dispositivo a un atacante con acceso físico"
    }
  ],
  "lastModified": "2026-06-17T04:10:12.057",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:a1_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26B4B1A2-26BB-4282-98E2-A1330A0B420A",
              "versionEndExcluding": "5.3.6.a1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:a1:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2E4D45D6-C702-4093-BD49-50E237FD4D94"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:t1_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58D149F6-8029-4DCB-AE37-F094CE09CCDC",
              "versionEndExcluding": "5.3.6.t1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:t1:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5AA9C614-61D6-4329-9BAE-EB24A68FAE6B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:x1_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "055D03D9-F4BE-4EAE-AF07-D8E807C0BF26",
              "versionEndExcluding": "5.3.8.x1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:x1:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "282CCA7C-F1B8-4E0D-923D-36C1E630EBF4"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:t2_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DECB887A-404E-4DFA-B1F0-B12DC2376487",
              "versionEndExcluding": "5.3.8.t2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:t2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1783634F-B40E-48C4-8102-8112C9BC95F4"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:t2pro_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "44D09A84-C0BE-4EB6-99F8-30184D7C8A40",
              "versionEndExcluding": "5.3.7.t2-pro"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:t2pro:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E31C853A-15FD-4D72-BA16-395A282E1E6B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@lenovo.com"
}