Description
A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to the Lenovo Personal Cloud Storage device firmware listed in the product table in LEN-73439.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-29807 | A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device. |
References
| Link | Providers |
|---|---|
| https://iknow.lenovo.com.cn/detail/dc_200017.html |
|
History
No history.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-04T03:38:50.310Z
Reserved: 2021-10-22T00:00:00.000Z
Link: CVE-2021-42852
No data.
Status : Modified
Published: 2022-05-18T16:15:08.417
Modified: 2024-11-21T06:28:13.683
Link: CVE-2021-42852
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD