3 results (0.003 seconds)

CVSS: 7.2EPSS: 0%CPEs: 6EXPL: 0

A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a specially crafted network configuration. This vulnerability is the same as CNVD-2020-68652. Se ha reportado una vulnerabilidad en Lenovo Smart Camera X3, X5 y C2E, que podría permitir una inyección de comandos al ajustar una configuración de red especialmente diseñada. Esta vulnerabilidad es la misma que CNVD-2020-68652. • https://iknow.lenovo.com.cn/detail/dc_198417.html https://www.cnvd.org.cn/flaw/show/CNVD-2020-68652 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 9.8EPSS: 0%CPEs: 6EXPL: 0

A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerability is the same as CNVD-2020-68651. Se ha reportado una vulnerabilidad en Lenovo Smart Camera X3, X5 y C2E, que podría permitir a un usuario no autorizado visualizar la información del dispositivo, alterar el contenido del firmware y la configuración del dispositivo. Esta vulnerabilidad es la misma que CNVD-2020-68651. • https://iknow.lenovo.com.cn/detail/dc_198417.html https://www.cnvd.org.cn/flaw/show/CNVD-2020-68651 • CWE-285: Improper Authorization •

CVSS: 6.8EPSS: 0%CPEs: 6EXPL: 0

A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow code execution if a specific file exists on the attached SD card. This vulnerability is the same as CNVD-2021-45262. Se ha reportado una vulnerabilidad en Lenovo Smart Camera X3, X5 y C2E, que podría permitir una ejecución de código si presenta un archivo específico en la tarjeta SD conectada. Esta vulnerabilidad es la misma que CNVD-2021-45262. • https://iknow.lenovo.com.cn/detail/dc_198417.html https://www.cnvd.org.cn/flaw/show/CNVD-2021-45262 • CWE-94: Improper Control of Generation of Code ('Code Injection') •