First published: Wed May 18 2022(Updated: )
An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo A1 Firmware | <5.3.6.a1 | |
Lenovo A1 Firmware | ||
Lenovo T1 | <5.3.6.t1 | |
Lenovo T1 Firmware | ||
Lenovo X1 Firmware | <5.3.8.x1 | |
Lenovo X1 | ||
Lenovo T2 Firmware | <5.3.8.t2 | |
Lenovo T2 Firmware | ||
Lenovo T2pro Firmware | <5.3.7.t2-pro | |
Lenovo T2pro Firmware |
Update to the Lenovo Personal Cloud Storage device firmware listed in the product table in LEN-73439.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42848 is an information disclosure vulnerability affecting some Lenovo Personal Cloud Storage devices.
An unauthenticated user can exploit CVE-2021-42848 to retrieve device and networking details.
CVE-2021-42848 affects Lenovo Personal Cloud Storage devices with the following firmware versions: A1 Firmware up to 5.3.6.a1, T1 Firmware up to 5.3.6.t1, X1 Firmware up to 5.3.8.x1, and T2pro Firmware up to 5.3.7.t2-pro.
CVE-2021-42848 has a severity rating of 5.3 (medium).
To fix CVE-2021-42848, Lenovo users should apply the latest firmware update provided by Lenovo.