CVE-2021-42849

MEDIUM

Lenovo A1 Firmware < 5.3.6.a1 - Authentication Bypass

Title source: rule
STIX 2.1

Description

A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://iknow.lenovo.com.cn/detail/dc_200017.html

Scores

CVSS v3 6.8
EPSS 0.0012
EPSS Percentile 30.3%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287 CWE-798
Status published
Products (5)
lenovo/a1_firmware < 5.3.6.a1
lenovo/t1_firmware < 5.3.6.t1
lenovo/t2_firmware < 5.3.8.t2
lenovo/t2pro_firmware < 5.3.7.t2-pro
lenovo/x1_firmware < 5.3.8.x1
Published May 18, 2022
Tracked Since Feb 18, 2026