VulnerabilityModified
CVE-2021-3616
A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration.
CRITICAL 9.8EPSS 0.92%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.92%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerability is the same as CNVD-2020-68651.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.92% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285
- Affected
- lenovo/smart camera c2e firmware · lenovo/smart camera x3 firmware · lenovo/smart camera x5 firmware
- Source
- psirt@lenovo.com
References
- https://iknow.lenovo.com.cn/detail/dc_198417.htmlVendor Advisory
- https://www.cnvd.org.cn/flaw/show/CNVD-2020-68651Not Applicable
- https://iknow.lenovo.com.cn/detail/dc_198417.htmlVendor Advisory
- https://www.cnvd.org.cn/flaw/show/CNVD-2020-68651Not Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.