Code Execution Vulnerability in Lenovo Smart Cameras
CVE-2021-3615
6.6MEDIUM
Key Information:
- Vendor
- Lenovo
- Vendor
- CVE Published:
- 17 August 2021
Summary
A code execution vulnerability has been reported in Lenovo's Smart Camera models X3, X5, and C2E. This flaw could potentially allow unauthorized code execution if a specific file is present on the SD card connected to the device, posing a significant security risk to users. With this vulnerability, malicious actors could exploit the situation to gain control over the device, thereby jeopardizing the privacy and security of the users' environments.
Affected Version(s)
Smart Camera X3, X5, and C2E firmware < 01.03.29.16
References
CVSS V3.1
Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lenovo thanks Charles Jiang and Xingcan Chen from Lenovo Global Security Lab for reporting these issues.