CVE-2021-42852: OS Command Injection
Published May 18, 2022
·Updated
A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device.
Affected Software
10 affected components
Lenovo A1 Firmware<5.3.6.a1
Lenovo A1
Lenovo T1 Firmware<5.3.6.t1
Lenovo T1
Lenovo X1 Firmware<5.3.8.x1
Lenovo X1
Lenovo T2 Firmware<5.3.8.t2
Lenovo T2
Lenovo T2pro Firmware<5.3.7.t2-pro
Lenovo T2pro
Remediation
Information
Update to the Lenovo Personal Cloud Storage device firmware listed in the product table in LEN-73439.
Event History
May 18, 2022
CVE Published
via MITRE·04:10 PM
Data Sourced
via MITRE·04:10 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Lenovo Personal Cloud Storage vulnerability?
The vulnerability ID for this Lenovo Personal Cloud Storage vulnerability is CVE-2021-42852.
2
What is the severity of CVE-2021-42852?
CVE-2021-42852 has a severity level of high.
3
How does the vulnerability in Lenovo Personal Cloud Storage devices occur?
The vulnerability in Lenovo Personal Cloud Storage devices occurs due to a command injection vulnerability.
4
Who can exploit CVE-2021-42852?
CVE-2021-42852 can be exploited by an authenticated user.
5
Is there a fix for CVE-2021-42852?
Yes, a fix is available for CVE-2021-42852. It is recommended to update the affected Lenovo Personal Cloud Storage devices to a version higher than 5.3.8.x1 for X1 Firmware, 5.3.8.t2 for T2 Firmware, and 5.3.7.t2-pro for T2pro Firmware.