ID

VAR-202108-0713


CVE

CVE-2021-3617


TITLE

plural  Lenovo Smart Camera  Command injection vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2021-011046

DESCRIPTION

A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a specially crafted network configuration. This vulnerability is the same as CNVD-2020-68652. (DoS) It may be in a state. Shenzhen Qiaoan Technology Co., Ltd. is a professional R&D and manufacturer of surveillance cameras, specializing in the production of Qiaoan surveillance, Qiaoan surveillance cameras, etc. Several webcams of Shenzhen Qiaoan Technology Co., Ltd. have information disclosure vulnerabilities, which can be exploited by attackers to obtain sensitive information

Trust: 2.25

sources: NVD: CVE-2021-3617 // JVNDB: JVNDB-2021-011046 // CNVD: CNVD-2020-68652 // VULMON: CVE-2021-3617

IOT TAXONOMY

category:['camera device']sub_category:camera

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:lenovomodel:smart camera c2escope:ltversion:01.03.29.16

Trust: 1.0

vendor:lenovomodel:smart camera x3scope:ltversion:01.03.29.16

Trust: 1.0

vendor:lenovomodel:smart camera x5scope:ltversion:01.03.29.16

Trust: 1.0

vendor:lenovomodel:smart camera x5scope: - version: -

Trust: 0.8

vendor:lenovomodel:smart camera c2escope: - version: -

Trust: 0.8

vendor:lenovomodel:smart camera x3scope: - version: -

Trust: 0.8

vendor:qiaoanmodel:ja-770scope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-c7mscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-c1kscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-f2tscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-f2cscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-g4rscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-f2t-lscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-q7mscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-q7scope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-f8scope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-f2escope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-q10scope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-q3scope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-c10scope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-f2t-nscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-q13cscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-f10scope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-c10escope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-f2rscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-q3rscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-c6kscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-f2kscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-q7kscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-f2k-4xscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-c5scope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-q8scope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-c9scope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-q5scope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-a6scope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-q7rscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-g4cscope:eqversion:01.03.29.14

Trust: 0.6

vendor:qiaoanmodel:ja-c6scope:eqversion:01.03.29.14

Trust: 0.6

sources: CNVD: CNVD-2020-68652 // JVNDB: JVNDB-2021-011046 // NVD: CVE-2021-3617

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-3617
value: HIGH

Trust: 1.0

psirt@lenovo.com: CVE-2021-3617
value: HIGH

Trust: 1.0

NVD: CVE-2021-3617
value: HIGH

Trust: 0.8

CNVD: CNVD-2020-68652
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202108-1582
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2021-3617
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2020-68652
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2021-3617
baseSeverity: HIGH
baseScore: 7.2
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 5.9
version: 3.1

Trust: 2.0

OTHER: JVNDB-2021-011046
baseSeverity: HIGH
baseScore: 7.2
vectorString: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-68652 // JVNDB: JVNDB-2021-011046 // CNNVD: CNNVD-202108-1582 // NVD: CVE-2021-3617 // NVD: CVE-2021-3617

PROBLEMTYPE DATA

problemtype:CWE-78

Trust: 1.0

problemtype:CWE-77

Trust: 1.0

problemtype:Command injection (CWE-77) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-011046 // NVD: CVE-2021-3617

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202108-1582

TYPE

command injection

Trust: 0.6

sources: CNNVD: CNNVD-202108-1582

PATCH

title:LEN-49262url:https://iknow.lenovo.com.cn/detail/dc_198417.html

Trust: 0.8

title:Lenovo Smart Camera Fixes for command injection vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=160997

Trust: 0.6

sources: JVNDB: JVNDB-2021-011046 // CNNVD: CNNVD-202108-1582

EXTERNAL IDS

db:NVDid:CVE-2021-3617

Trust: 3.4

db:CNVDid:CNVD-2020-68652

Trust: 2.3

db:JVNDBid:JVNDB-2021-011046

Trust: 0.8

db:CNNVDid:CNNVD-202108-1582

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

db:VULMONid:CVE-2021-3617

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2020-68652 // VULMON: CVE-2021-3617 // JVNDB: JVNDB-2021-011046 // CNNVD: CNNVD-202108-1582 // NVD: CVE-2021-3617

REFERENCES

url:https://www.cnvd.org.cn/flaw/show/cnvd-2020-68652

Trust: 1.7

url:https://iknow.lenovo.com.cn/detail/dc_198417.html

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-3617

Trust: 0.8

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2021-3617 // JVNDB: JVNDB-2021-011046 // CNNVD: CNNVD-202108-1582 // NVD: CVE-2021-3617

SOURCES

db:OTHERid: -
db:CNVDid:CNVD-2020-68652
db:VULMONid:CVE-2021-3617
db:JVNDBid:JVNDB-2021-011046
db:CNNVDid:CNNVD-202108-1582
db:NVDid:CVE-2021-3617

LAST UPDATE DATE

2025-01-30T21:25:07.228000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-68652date:2020-12-03T00:00:00
db:VULMONid:CVE-2021-3617date:2021-08-17T00:00:00
db:JVNDBid:JVNDB-2021-011046date:2022-07-15T04:57:00
db:CNNVDid:CNNVD-202108-1582date:2021-08-31T00:00:00
db:NVDid:CVE-2021-3617date:2024-11-21T06:21:59.567

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-68652date:2021-01-04T00:00:00
db:VULMONid:CVE-2021-3617date:2021-08-17T00:00:00
db:JVNDBid:JVNDB-2021-011046date:2022-07-15T00:00:00
db:CNNVDid:CNNVD-202108-1582date:2021-08-17T00:00:00
db:NVDid:CVE-2021-3617date:2021-08-17T17:15:07.610