02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
02 Description
CNA: talosStack-based buffer overflow vulnerability exists in how the CMA readfile function of Garrett Metal Detectors iC Module CMA Version 5.0 is used at various locations. The Garrett iC Module exposes an
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Not assessed. CISA has not published an exploitation assessment for this record, and it is not in the KEV catalog. That is an absence of assessment, not a finding of no risk.
- SSVC decision
- Not assessed by CISA
- EPSS probability
- 0.95% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 58.9% of scored records. A rank, not a probability.
- NVD base score
- 7.2 (CVSS v3.x), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- NVD analysis status
- Modified. NVD last modified this record on 2026-06-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.1
- Published
- 2021-12-22 18:06Z4 YR AGO
- Last updated
- 2024-08-03 18:30Z2 YR AGO
- Reserved
- 2021-01-04
- Assigning CNA
- talos
- Record state
- PUBLISHED
- Severity
- High (CVSS 8.2)
- CNA CVSS vector
- CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Weaknesses
- CWE-121Stack-based Buffer OverflowVariant
- CWE-787Out-of-bounds WriteBase
- Data version
- 5.1
- Document digest
- 2d9b4484ccb363c67f7617322e91006fbd81a65f6a63dd4416d01611e5c20fca
05 Affected products
PAIRS: 1VendorProductVersionsPlatforms