CRITICAL · 9.4

CVE-2021-3616

A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerabilit...

Vulnerability Description

A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerability is the same as CNVD-2020-68651.

CVSS Score

9.4

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LenovoSmart Camera C2E Firmware< 01.03.29.16
LenovoSmart Camera C2E-
LenovoSmart Camera X3 Firmware< 01.03.29.16
LenovoSmart Camera X3-
LenovoSmart Camera X5 Firmware< 01.03.29.16
LenovoSmart Camera X5-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-3616?

CVE-2021-3616 is a vulnerability with a CVSS score of 9.4 (CRITICAL). A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerabilit...

How severe is CVE-2021-3616?

CVE-2021-3616 has been rated CRITICAL with a CVSS base score of 9.4/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-3616?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Smart Camera C2E Firmware, Lenovo Smart Camera C2E, Lenovo Smart Camera X3 Firmware, Lenovo Smart Camera X3, Lenovo Smart Camera X5 Firmware.