PT-2021-14830 · Garrett Metal Detectors · Ic Module Cma

Matt Wiseman

·

Published

2021-12-22

·

Updated

2022-08-31

·

CVE-2021-21904

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iC Module CMA version 5.0
Description A directory traversal vulnerability exists in the CMA CLI setenv command of Garrett Metal Detectors’ iC Module CMA. An attacker can provide malicious input to trigger this vulnerability.
Recommendations For iC Module CMA version 5.0, consider restricting access to the setenv command in the CMA CLI to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2021-21904

Affected Products

Ic Module Cma