cvelist/2021/3xxx/CVE-2021-3616.json
2021-08-17 17:00:58 +00:00

103 lines
3.2 KiB
JSON

{
"CVE_data_meta": {
"ASSIGNER": "psirt@lenovo.com",
"ID": "CVE-2021-3616",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Smart Camera X3, X5, and C2E firmware",
"version": {
"version_data": [
{
"version_affected": "<",
"version_value": "01.03.29.16"
}
]
}
}
]
},
"vendor_name": "Lenovo"
}
]
}
},
"credit": [
{
"lang": "eng",
"value": " Lenovo thanks Charles Jiang and Xingcan Chen from Lenovo Global Security Lab for reporting these issues."
}
],
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerability is the same as CNVD-2020-68651."
}
]
},
"generator": {
"engine": "Vulnogram 0.0.9"
},
"impact": {
"cvss": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.4,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "LOW",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H",
"version": "3.1"
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-285 Improper Authorization"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"url": "https://iknow.lenovo.com.cn/detail/dc_198417.html",
"name": "https://iknow.lenovo.com.cn/detail/dc_198417.html"
},
{
"refsource": "MISC",
"url": "https://www.cnvd.org.cn/flaw/show/CNVD-2020-68651",
"name": "https://www.cnvd.org.cn/flaw/show/CNVD-2020-68651"
}
]
},
"solution": [
{
"lang": "eng",
"value": "Update to Lenovo Smart Camera X3, X5, and C2E firmware version 01.03.29.16 or later."
}
],
"source": {
"advisory": "LEN-49262",
"discovery": "UNKNOWN"
}
}