CVE-2021-21904

HIGH

Garrett iC Module CMA 5.0 - Path Traversal via CMA CLI setenv Command

Title source: llm
STIX 2.1

Description

A directory traversal vulnerability exists in the CMA CLI setenv command of Garrett Metal Detectors’ iC Module CMA Version 5.0. An attacker can provide malicious input to trigger this vulnerability

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1356

Scores

CVSS v3 7.2
EPSS 0.0282
EPSS Percentile 84.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
garrett/ic_module_cma 5.0
Published Dec 22, 2021
Tracked Since Feb 18, 2026