Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Garrett

First CVE: Dec 22, 2021Active for: 5 yearsTotal CVEs: 9

Garrett's vulnerability profile centers on a modestly represented line of industrial control modules and firmware, which despite limited scale occupy a specialized and mission-critical niche in detection and access-control systems. The exposure recurs through foundational memory-safety and input-validation weaknesses—path traversal, buffer overflows, stack overflows, and out-of-bounds writes—alongside authentication bypasses, reflecting the constraints of embedded firmware development. Vulnerabilities affecting this vendor skew toward serious outcomes; live exploitation activity, severity, and current exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Garrett over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 22, 2021
4 years ago
Most Recent CVE
Dec 22, 2021
1,676 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-21903CRITICAL
A stack-based buffer overflow vulnerability exists in the CMA check_udp_crc function of Garrett Metal Detectors’ iC Module CMA Version 5.0. A specially-crafted packet can lead to a
Dec 22, 20219.830NONO
CVE-2021-21901HIGH
A stack-based buffer overflow vulnerability exists in the CMA check_udp_crc function of Garrett Metal Detectors’ iC Module CMA Version 5.0. A specially-crafted packet can lead to a
Dec 22, 20218.827NONO
CVE-2021-21902HIGH
An authentication bypass vulnerability exists in the CMA run_server_6877 functionality of Garrett Metal Detectors iC Module CMA Version 5.0. A properly-timed network connection can
Dec 22, 20218.126NONO
CVE-2021-21909HIGH
Specially-crafted command line arguments can lead to arbitrary file deletion in the del .cnt|.log file delete command. An attacker can provide malicious inputs to trigger this vuln
Dec 22, 20218.125NONO
CVE-2021-21904HIGH
A directory traversal vulnerability exists in the CMA CLI setenv command of Garrett Metal Detectors’ iC Module CMA Version 5.0. An attacker can provide malicious input to trigger t
Dec 22, 20217.224NONO
CVE-2021-21906HIGH
Stack-based buffer overflow vulnerability exists in how the CMA readfile function of Garrett Metal Detectors iC Module CMA Version 5.0 is used at various locations. The Garrett iC
Dec 22, 20217.223NONO
CVE-2021-21905HIGH
Stack-based buffer overflow vulnerability exists in how the CMA readfile function of Garrett Metal Detectors iC Module CMA Version 5.0 is used at various locations. The Garrett iC
Dec 22, 20217.223NONO
CVE-2021-21908MEDIUM
Specially-crafted command line arguments can lead to arbitrary file deletion. The handle_delete function does not attempt to sanitize or otherwise validate the contents of the [fil
Dec 22, 20216.522NONO
CVE-2021-21907MEDIUM
A directory traversal vulnerability exists in the CMA CLI getenv command functionality of Garrett Metal Detectors’ iC Module CMA Version 5.0. A specially-crafted command line argum
Dec 22, 20214.921NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
22%
67%
11%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (22.2%)
High5 (55.6%)
None2 (22.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Garrett.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Garrett — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Garrett's Products

View all 1 CNAs →

Top CWEs