CVE-2021-42849
EUVD-2021-2980418.05.2022, 16:15
A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lenovo | a1_firmware | 𝑥 < 5.3.6.a1 |
| lenovo | t1_firmware | 𝑥 < 5.3.6.t1 |
| lenovo | x1_firmware | 𝑥 < 5.3.8.x1 |
| lenovo | t2_firmware | 𝑥 < 5.3.8.t2 |
| lenovo | t2pro_firmware | 𝑥 < 5.3.7.t2-pro |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-798 - Use of Hard-coded CredentialsThe software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.