PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-43692 Dover Fueling Solutions (DFS) CVE debrief

A critical authentication bypass vulnerability in Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE allows remote attackers to gain full administrative privileges by directly requesting protected resource subpages via URL manipulation. The flaw, published September 24, 2024, enables unauthenticated network-based access to sensitive console functions without requiring credentials or user interaction.

Vendor
Dover Fueling Solutions (DFS)
Product
ProGauge MAGLINK LX CONSOLE
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-09-24
Original CVE updated
2024-09-24
Advisory published
2024-09-24
Advisory updated
2024-09-24

Who should care

Organizations operating fueling station infrastructure, petroleum retail networks, fleet fueling operations, and industrial fuel management systems utilizing Dover Fueling Solutions MAGLINK LX or LX4 consoles. Critical infrastructure operators in the energy sector should prioritize patching due to potential operational disruption and safety implications.

Technical summary

The ProGauge MAGLINK LX CONSOLE web interface fails to enforce authentication on resource subpages, allowing direct URL access with full administrative privileges. An unauthenticated remote attacker can craft HTTP requests to protected endpoints without credential validation, resulting in complete confidentiality, integrity, and availability compromise of the console. The vulnerability is network-exploitable with low attack complexity and no required privileges or user interaction.

Defensive priority

critical

Recommended defensive actions

  • Apply vendor patch version 4.19.10 through Dover Fueling Solutions authorized service organizations; contact DFS customer support at 877-679-8324 for North American installation assistance
  • Deploy MAGLINK consoles behind network firewalls with strict ingress filtering to limit exposure
  • Implement network segmentation to isolate fueling system consoles from untrusted networks
  • Monitor for and install security updates on a timely basis per vendor guidance
  • Consider operating MAGLINK consoles offline or air-gapped where operational requirements permit
  • Review CISA ICS recommended practices for industrial control system defense in depth
  • resourceLinkAnnotations: [source-item, ref-4, ref-5, ref-6, ref-7, ref-9, ref-10]

Evidence notes

CISA ICS advisory ICSA-24-268-04 documents this vulnerability with CVSS 3.1 score 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Affected versions include ProGauge MAGLINK LX CONSOLE ≤3.4.2.2.6 and MAGLINK LX4 CONSOLE ≤4.17.9e. The vendor released patched version 4.19.10.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-43692 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-43692

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-43692 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-43692

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-268-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.