VYPR
Medium severity6.8NVD Advisory· Published May 18, 2022· Updated Jun 17, 2026

CVE-2021-42849

CVE-2021-42849

Description

A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.

Affected products

11
  • cpe:2.3:o:lenovo:a1_firmware:*:*:*:*:*:*:*:*
    Range: <5.3.6.a1
  • cpe:2.3:o:lenovo:t1_firmware:*:*:*:*:*:*:*:*
    Range: <5.3.6.t1
  • cpe:2.3:o:lenovo:t2_firmware:*:*:*:*:*:*:*:*
    Range: <5.3.8.t2
  • cpe:2.3:o:lenovo:t2pro_firmware:*:*:*:*:*:*:*:*
    Range: <5.3.7.t2-pro
  • cpe:2.3:o:lenovo:x1_firmware:*:*:*:*:*:*:*:*
    Range: <5.3.8.x1
  • Lenovo/Personal Cloud Storagellm-fuzzy6 versions
    (expand)+ 5 more
    • (no CPE)
    • (no CPE)range: unspecified
    • (no CPE)range: unspecified
    • (no CPE)range: unspecified
    • (no CPE)range: unspecified
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.