Security News > 2021 > December > Garrett Walk-Through Metal Detectors Can Be Hacked Remotely

Garrett Walk-Through Metal Detectors Can Be Hacked Remotely
2021-12-28 01:32

A number of security flaws have been uncovered in a networking component in Garrett Metal Detectors that could allow remote attackers to bypass authentication requirements, tamper with metal detector configurations, and even execute arbitrary code on the devices.

"An attacker could manipulate this module to remotely monitor statistics on the metal detector, such as whether the alarm has been triggered or how many visitors have walked through," Cisco Talos noted in a disclosure publicized last week.

"They could also make configuration changes, such as altering the sensitivity level of a device, which potentially poses a security risk to users who rely on these metal detectors."

The flaws reside in Garrett iC Module, which enables users to communicate to walk-through metal detectors like Garrett PD 6500i or Garrett MZ 6100 using a computer through the network, either wired or wirelessly.

CVE-2021-21901, CVE-2021-21903, CVE-2021-21905, and CVE-2021-21906 - Stack-based buffer overflow vulnerabilities that can be triggered by sending a malicious packet to the device.

Successful exploitation of the aforementioned flaws in iC Module CMA version 5.0 could allow an attacker to hijack an authenticated user's session, read, write, or delete arbitrary files on the device, and worse, lead to remote code execution.


News URL

https://thehackernews.com/2021/12/garrett-walk-through-metal-detectors.html

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-12-22 CVE-2021-21906 Out-of-bounds Write vulnerability in Garrett IC Module CMA 5.0
Stack-based buffer overflow vulnerability exists in how the CMA readfile function of Garrett Metal Detectors iC Module CMA Version 5.0 is used at various locations.
network
low complexity
garrett CWE-787
7.2
2021-12-22 CVE-2021-21905 Out-of-bounds Write vulnerability in Garrett IC Module CMA 5.0
Stack-based buffer overflow vulnerability exists in how the CMA readfile function of Garrett Metal Detectors iC Module CMA Version 5.0 is used at various locations.
network
low complexity
garrett CWE-787
7.2
2021-12-22 CVE-2021-21903 Out-of-bounds Write vulnerability in Garrett IC Module CMA 5.0
A stack-based buffer overflow vulnerability exists in the CMA check_udp_crc function of Garrett Metal Detectors’ iC Module CMA Version 5.0.
network
low complexity
garrett CWE-787
critical
9.8
2021-12-22 CVE-2021-21901 Out-of-bounds Write vulnerability in Garrett IC Module CMA 5.0
A stack-based buffer overflow vulnerability exists in the CMA check_udp_crc function of Garrett Metal Detectors’ iC Module CMA Version 5.0.
network
low complexity
garrett CWE-787
8.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Garrett 2 0 2 6 1 9