CVE-2021-42848: Medium severity lenovo a1 firmware vulnerability
An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-42848?
CVE-2021-42848 is an information disclosure vulnerability affecting some Lenovo Personal Cloud Storage devices.
How can an unauthenticated user exploit CVE-2021-42848?
An unauthenticated user can exploit CVE-2021-42848 to retrieve device and networking details.
Which Lenovo devices are affected by CVE-2021-42848?
CVE-2021-42848 affects Lenovo Personal Cloud Storage devices with the following firmware versions: A1 Firmware up to 5.3.6.a1, T1 Firmware up to 5.3.6.t1, X1 Firmware up to 5.3.8.x1, and T2pro Firmware up to 5.3.7.t2-pro.
What is the severity of CVE-2021-42848?
CVE-2021-42848 has a severity rating of 5.3 (medium).
How can I fix CVE-2021-42848?
To fix CVE-2021-42848, Lenovo users should apply the latest firmware update provided by Lenovo.