CRITICAL🇵🇱 Wersja polska

CVE-2024-39375

CVSS 9.3v4.0pub. 2024-06-27upd. 2024-11-21

TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileges.

🤖 AI Analysis
How it works

The vulnerability stems from improper authentication verification (CWE-603 — Use of Client-Side Authentication), allowing an attacker to remotely bypass access control mechanisms. An attacker can obtain full administrator privileges without needing valid authentication credentials. The attack requires no interaction from authorized users or special preconditions.

Impact

An attacker gains full administrative access to the device, enabling control over the FM transmitter, modification of its configuration, or disruption of its operation. This can lead to unauthorized interference with broadcasting infrastructure.

Mitigation & patch

Apply patches available from the manufacturer in accordance with references provided. Additionally, it is recommended to restrict network access to device management panels exclusively to trusted networks or via VPN, in accordance with CISA ICS Advisory ICSA-24-179-01 recommendations.

Who is affected

Markoni Markoni-D (Compact) and Markoni Markoni-DH (Exciter+Amplifiers) devices — versions specified in manufacturer references (CISA advisory ICSA-24-179-01)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Markoni D \(compact\)

    HW
    Markoni
    all versions
  • Markoni D \(compact\) Firmware

    OS
    Markoni
    < 2.0.1
  • Markoni Dh \(exciter\+amplifiers\)

    HW
    Markoni
    all versions
  • Markoni Dh \(exciter\+amplifiers\) Firmware

    OS
    Markoni
    < 2.0.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-39373CRITICAL9.3PL ✓same product

Command injection w nadajnikach FM TELSAT marKoni — nieautoryzowany dostęp administracyjny

CVE-2024-39374CRITICAL9.3PL ✓same product

Ukryte konto admina z zakodowanymi danymi w nadajnikach FM TELSAT marKoni

CVE-2024-39376CRITICAL9.3PL ✓same product

Nieautoryzowany dostęp w nadajnikach FM TELSAT marKoni