TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials.
In marKoni FM transmitter software, there is a hidden administrative account whose login credentials are hard-coded in the firmware (CWE-798). An attacker knowing these credentials can log in to the device without having any permissions or user interaction. Access is possible remotely over the network without additional prerequisites.
An attacker gains full administrative access to the device, which allows modification of the transmitter configuration, disruption or interruption of FM signal transmission, and potential use of the device as an entry point to the operator's network.
Apply patches available from the manufacturer in accordance with the references. Additionally, it is recommended to isolate devices from the public internet, place them behind a firewall, and restrict access to the management interface exclusively to trusted IP addresses.
Markoni Markoni-D (Compact) Firmware and Markoni Markoni-Dh (Exciter+Amplifiers) Firmware — specific versions indicated in the manufacturer's references (ICS Advisory ICSA-24-179-01).
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMarkoni D \(compact\)
HWMarkoniall versionsMarkoni D \(compact\) Firmware
OSMarkoni< 2.0.1Markoni Dh \(exciter\+amplifiers\)
HWMarkoniall versionsMarkoni Dh \(exciter\+amplifiers\) Firmware
OSMarkoni< 2.0.1
Related vulnerabilities
Command injection w nadajnikach FM TELSAT marKoni — nieautoryzowany dostęp administracyjny
Pominięcie uwierzytelniania w nadajnikach FM TELSAT Markoni
Nieautoryzowany dostęp w nadajnikach FM TELSAT marKoni