CVE-2021-21902 is an authentication bypass vulnerability affecting the CMA run_server_6877 functionality in Garrett Metal Detectors iC Module CMA Version 5.0. An attacker can exploit this by sending a properly-timed sequence of network requests, leading to session hijacking. This vulnerability is rated 8.1 HIGH on the CVSS scale, indicating a severe risk with high impact on confidentiality, integrity, and availability, requiring no user interaction and having high attack complexity. There is no evidence of active exploitation, nor are there publicly available exploit codes like Metasploit or Nuclei modules; however, it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0CPE matchmatch criteria | cpe:2.3:o:garrett:ic_module_cma:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.