PatchSiren cyber security CVE debrief
CVE-2024-43692 Dover Fueling Solutions (DFS) CVE debrief
A critical authentication bypass vulnerability in Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE allows remote attackers to gain full administrative privileges by directly requesting protected resource subpages via URL manipulation. The flaw, published September 24, 2024, enables unauthenticated network-based access to sensitive console functions without requiring credentials or user interaction.
- Vendor
- Dover Fueling Solutions (DFS)
- Product
- ProGauge MAGLINK LX CONSOLE
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-09-24
- Original CVE updated
- 2024-09-24
- Advisory published
- 2024-09-24
- Advisory updated
- 2024-09-24
Who should care
Organizations operating fueling station infrastructure, petroleum retail networks, fleet fueling operations, and industrial fuel management systems utilizing Dover Fueling Solutions MAGLINK LX or LX4 consoles. Critical infrastructure operators in the energy sector should prioritize patching due to potential operational disruption and safety implications.
Technical summary
The ProGauge MAGLINK LX CONSOLE web interface fails to enforce authentication on resource subpages, allowing direct URL access with full administrative privileges. An unauthenticated remote attacker can craft HTTP requests to protected endpoints without credential validation, resulting in complete confidentiality, integrity, and availability compromise of the console. The vulnerability is network-exploitable with low attack complexity and no required privileges or user interaction.
Defensive priority
critical
Recommended defensive actions
- Apply vendor patch version 4.19.10 through Dover Fueling Solutions authorized service organizations; contact DFS customer support at 877-679-8324 for North American installation assistance
- Deploy MAGLINK consoles behind network firewalls with strict ingress filtering to limit exposure
- Implement network segmentation to isolate fueling system consoles from untrusted networks
- Monitor for and install security updates on a timely basis per vendor guidance
- Consider operating MAGLINK consoles offline or air-gapped where operational requirements permit
- Review CISA ICS recommended practices for industrial control system defense in depth
- resourceLinkAnnotations: [source-item, ref-4, ref-5, ref-6, ref-7, ref-9, ref-10]
Evidence notes
CISA ICS advisory ICSA-24-268-04 documents this vulnerability with CVSS 3.1 score 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Affected versions include ProGauge MAGLINK LX CONSOLE ≤3.4.2.2.6 and MAGLINK LX4 CONSOLE ≤4.17.9e. The vendor released patched version 4.19.10.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-43692 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-43692
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-43692 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-43692
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-268-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.