CRITICAL🇵🇱 Wersja polska

CVE-2024-39374

CVSS 9.3v4.0pub. 2024-06-27upd. 2024-11-21

TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials.

🤖 AI Analysis
How it works

In marKoni FM transmitter software, there is a hidden administrative account whose login credentials are hard-coded in the firmware (CWE-798). An attacker knowing these credentials can log in to the device without having any permissions or user interaction. Access is possible remotely over the network without additional prerequisites.

Impact

An attacker gains full administrative access to the device, which allows modification of the transmitter configuration, disruption or interruption of FM signal transmission, and potential use of the device as an entry point to the operator's network.

Mitigation & patch

Apply patches available from the manufacturer in accordance with the references. Additionally, it is recommended to isolate devices from the public internet, place them behind a firewall, and restrict access to the management interface exclusively to trusted IP addresses.

Who is affected

Markoni Markoni-D (Compact) Firmware and Markoni Markoni-Dh (Exciter+Amplifiers) Firmware — specific versions indicated in the manufacturer's references (ICS Advisory ICSA-24-179-01).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Markoni D \(compact\)

    HW
    Markoni
    all versions
  • Markoni D \(compact\) Firmware

    OS
    Markoni
    < 2.0.1
  • Markoni Dh \(exciter\+amplifiers\)

    HW
    Markoni
    all versions
  • Markoni Dh \(exciter\+amplifiers\) Firmware

    OS
    Markoni
    < 2.0.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-39373CRITICAL9.3PL ✓same product

Command injection w nadajnikach FM TELSAT marKoni — nieautoryzowany dostęp administracyjny

CVE-2024-39375CRITICAL9.3PL ✓same product

Pominięcie uwierzytelniania w nadajnikach FM TELSAT Markoni

CVE-2024-39376CRITICAL9.3PL ✓same product

Nieautoryzowany dostęp w nadajnikach FM TELSAT marKoni