CVE-2021-42848

An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
lenovoa1_firmware
𝑥
< 5.3.6.a1
lenovot1_firmware
𝑥
< 5.3.6.t1
lenovox1_firmware
𝑥
< 5.3.8.x1
lenovot2_firmware
𝑥
< 5.3.8.t2
lenovot2pro_firmware
𝑥
< 5.3.7.t2-pro
𝑥
= Vulnerable software versions