TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileges.
The vulnerability stems from improper authentication verification (CWE-603 — Use of Client-Side Authentication), allowing an attacker to remotely bypass access control mechanisms. An attacker can obtain full administrator privileges without needing valid authentication credentials. The attack requires no interaction from authorized users or special preconditions.
An attacker gains full administrative access to the device, enabling control over the FM transmitter, modification of its configuration, or disruption of its operation. This can lead to unauthorized interference with broadcasting infrastructure.
Apply patches available from the manufacturer in accordance with references provided. Additionally, it is recommended to restrict network access to device management panels exclusively to trusted networks or via VPN, in accordance with CISA ICS Advisory ICSA-24-179-01 recommendations.
Markoni Markoni-D (Compact) and Markoni Markoni-DH (Exciter+Amplifiers) devices — versions specified in manufacturer references (CISA advisory ICSA-24-179-01)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMarkoni D \(compact\)
HWMarkoniall versionsMarkoni D \(compact\) Firmware
OSMarkoni< 2.0.1Markoni Dh \(exciter\+amplifiers\)
HWMarkoniall versionsMarkoni Dh \(exciter\+amplifiers\) Firmware
OSMarkoni< 2.0.1
Related vulnerabilities
Command injection w nadajnikach FM TELSAT marKoni — nieautoryzowany dostęp administracyjny
Ukryte konto admina z zakodowanymi danymi w nadajnikach FM TELSAT marKoni
Nieautoryzowany dostęp w nadajnikach FM TELSAT marKoni