Garrettcom develops industrial networking and managed-switch firmware for its Magnum product line, which serves critical infrastructure and automation environments. The observed vulnerability signal centers on cross-site scripting weaknesses in its management software interfaces, a pattern consistent with web-facing administrative access points in networked devices.
The number and severity of CVEs published that impact products developed by Garrettcom over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-3014HIGH The Management Software application in GarrettCom Magnum MNS-6K before 4.4.0, and 14.x before 14.4.0, has a hardcoded password for an administrative account, which allows local use | Sep 4, 2012 | 7.7 | 23 | NO | NO |
CVE-2015-3959HIGH The firmware in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches has a hardcoded serial-console password for a privileged account, which might allow physical | Aug 4, 2015 | 7.2 | 18 | NO | NO |
CVE-2015-3960MEDIUM The firmware in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches uses hardcoded RSA private keys and certificates across different customers' installations, | Aug 4, 2015 | 4.3 | 14 | NO | NO |
CVE-2015-3942MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the web-server component in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches allow remote attackers to | Aug 4, 2015 | 4.3 | 14 | NO | NO |
The web-server component in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches allows remote authenticated users to cause a denial of service (memory corruptio | Aug 4, 2015 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Garrettcom.
Media articles that mention a CVE ID that affects a product developed by Garrettcom — matched by CVE ID, not by vendor name.