CVE-2021-42850
CVE-2021-42850
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
18 May 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Lenovo · Personal Cloud Storage A1Lenovo · Personal Cloud Storage T1Lenovo · Personal Cloud Storage T2Lenovo · Personal Cloud Storage T2ProLenovo · Personal Cloud Storage X1Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →