Garrett's vulnerability profile centers on a modestly represented line of industrial control modules and firmware, which despite limited scale occupy a specialized and mission-critical niche in detection and access-control systems. The exposure recurs through foundational memory-safety and input-validation weaknesses—path traversal, buffer overflows, stack overflows, and out-of-bounds writes—alongside authentication bypasses, reflecting the constraints of embedded firmware development. Vulnerabilities affecting this vendor skew toward serious outcomes; live exploitation activity, severity, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Garrett over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21903CRITICAL A stack-based buffer overflow vulnerability exists in the CMA check_udp_crc function of Garrett Metal Detectors’ iC Module CMA Version 5.0. A specially-crafted packet can lead to a | Dec 22, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-21901HIGH A stack-based buffer overflow vulnerability exists in the CMA check_udp_crc function of Garrett Metal Detectors’ iC Module CMA Version 5.0. A specially-crafted packet can lead to a | Dec 22, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-21902HIGH An authentication bypass vulnerability exists in the CMA run_server_6877 functionality of Garrett Metal Detectors iC Module CMA Version 5.0. A properly-timed network connection can | Dec 22, 2021 | 8.1 | 26 | NO | NO |
CVE-2021-21909HIGH Specially-crafted command line arguments can lead to arbitrary file deletion in the del .cnt|.log file delete command. An attacker can provide malicious inputs to trigger this vuln | Dec 22, 2021 | 8.1 | 25 | NO | NO |
CVE-2021-21904HIGH A directory traversal vulnerability exists in the CMA CLI setenv command of Garrett Metal Detectors’ iC Module CMA Version 5.0. An attacker can provide malicious input to trigger t | Dec 22, 2021 | 7.2 | 24 | NO | NO |
CVE-2021-21906HIGH Stack-based buffer overflow vulnerability exists in how the CMA readfile function of Garrett Metal Detectors iC Module CMA Version 5.0 is used at various locations. The Garrett iC | Dec 22, 2021 | 7.2 | 23 | NO | NO |
CVE-2021-21905HIGH Stack-based buffer overflow vulnerability exists in how the CMA readfile function of Garrett Metal Detectors iC Module CMA Version 5.0 is used at various locations. The Garrett iC | Dec 22, 2021 | 7.2 | 23 | NO | NO |
CVE-2021-21908MEDIUM Specially-crafted command line arguments can lead to arbitrary file deletion. The handle_delete function does not attempt to sanitize or otherwise validate the contents of the [fil | Dec 22, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-21907MEDIUM A directory traversal vulnerability exists in the CMA CLI getenv command functionality of Garrett Metal Detectors’ iC Module CMA Version 5.0. A specially-crafted command line argum | Dec 22, 2021 | 4.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Garrett.
Media articles that mention a CVE ID that affects a product developed by Garrett — matched by CVE ID, not by vendor name.