PT-2021-14828 · Garrett Metal Detectors · Garrett Metal Detectors Ic Module Cma
Matt Wiseman
·
Published
2021-12-22
·
Updated
2022-08-31
·
CVE-2021-21902
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Garrett Metal Detectors iC Module CMA version 5.0
Description
An authentication bypass issue exists in the CMA
run server 6877 functionality. A properly-timed network connection can lead to authentication bypass via session hijacking. An attacker can send a sequence of requests to trigger this issue.Recommendations
For Garrett Metal Detectors iC Module CMA version 5.0, consider disabling the
run server 6877 functionality as a temporary workaround until a patch is available. Restrict access to the affected module to minimize the risk of exploitation. Avoid using the affected functionality in the CMA until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Garrett Metal Detectors Ic Module Cma