PT-2021-14828 · Garrett Metal Detectors · Garrett Metal Detectors Ic Module Cma

Matt Wiseman

·

Published

2021-12-22

·

Updated

2022-08-31

·

CVE-2021-21902

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Garrett Metal Detectors iC Module CMA version 5.0
Description An authentication bypass issue exists in the CMA run server 6877 functionality. A properly-timed network connection can lead to authentication bypass via session hijacking. An attacker can send a sequence of requests to trigger this issue.
Recommendations For Garrett Metal Detectors iC Module CMA version 5.0, consider disabling the run server 6877 functionality as a temporary workaround until a patch is available. Restrict access to the affected module to minimize the risk of exploitation. Avoid using the affected functionality in the CMA until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2021-21902

Affected Products

Garrett Metal Detectors Ic Module Cma