A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device.
2022-05-18T16:15:08.417
2024-11-21T06:28:13.683
Modified
CVSSv3.1: 8.0 (HIGH)
AV:A/AC:L/Au:S/C:C/I:C/A:C
5.1
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | lenovo | a1_firmware | < 5.3.6.a1 | Yes |
Hardware | lenovo | a1 | - | No |
Operating System | lenovo | t1_firmware | < 5.3.6.t1 | Yes |
Hardware | lenovo | t1 | - | No |
Operating System | lenovo | x1_firmware | < 5.3.8.x1 | Yes |
Hardware | lenovo | x1 | - | No |
Operating System | lenovo | t2_firmware | < 5.3.8.t2 | Yes |
Hardware | lenovo | t2 | - | No |
Operating System | lenovo | t2pro_firmware | < 5.3.7.t2-pro | Yes |
Hardware | lenovo | t2pro | - | No |