TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings and could allow an attacker to gain unauthorized access to the system with administrative privileges.
An attacker can exploit the vulnerability by manipulating device settings, which leads to injection and execution of arbitrary system commands (command injection, CWE-77). The attack is possible remotely, without authentication and without user interaction, making it particularly dangerous in industrial control system (ICS) environments. The vulnerability results from improper validation of input data passed to system commands.
A successful attack allows an attacker to take full control of the device with administrator privileges, which in an FM transmitter environment can lead to disruption or interruption of radio transmission and further compromise of the infrastructure.
Patches available from the manufacturer should be applied according to the references — detailed guidelines are contained in the CISA ICS advisory ICSA-24-179-01 (https://www.cisa.gov/news-events/ics-advisories/icsa-24-179-01). It is also recommended to isolate devices from public networks and restrict network access to trusted hosts.
Markoni Markoni-D (Compact) Firmware devices, Markoni Markoni-Dh (Exciter+Amplifiers) Firmware — specific versions indicated in the manufacturer's references (CISA ICS advisory ICSA-24-179-01)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMarkoni D \(compact\)
HWMarkoniall versionsMarkoni D \(compact\) Firmware
OSMarkoni< 2.0.1Markoni Dh \(exciter\+amplifiers\)
HWMarkoniall versionsMarkoni Dh \(exciter\+amplifiers\) Firmware
OSMarkoni< 2.0.1
Related vulnerabilities
Ukryte konto admina z zakodowanymi danymi w nadajnikach FM TELSAT marKoni
Pominięcie uwierzytelniania w nadajnikach FM TELSAT Markoni
Nieautoryzowany dostęp w nadajnikach FM TELSAT marKoni