PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-1491 Electrolink CVE debrief

A critical unauthenticated file upload vulnerability affects 24 Electrolink FM/DAB/TV transmitter models. The devices expose an unprotected endpoint allowing MPFS (Microchip Proprietary File System) binary image uploads without authentication. An attacker can exploit this to overwrite flash program memory containing the web server's main interfaces, leading to arbitrary code execution. The vulnerability stems from the MPFS2 file system module, which provides read-only storage for the HTTP2 web server and SNMP modules but can be abused to modify internal flash memory. Electrolink has not responded to CISA coordination requests, leaving affected users without vendor-provided mitigations. The broad product coverage across DAB, FM, and TV transmitter lines with all versions affected indicates extensive exposure in broadcast infrastructure environments.

Vendor
Electrolink
Product
10W Compact DAB Transmitter
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-16
Original CVE updated
2024-04-16
Advisory published
2024-04-16
Advisory updated
2024-04-16

Who should care

Broadcast station engineers, critical infrastructure security teams, OT/ICS security practitioners, telecommunications regulators, and organizations operating Electrolink transmission equipment

Technical summary

The vulnerability exists in the MPFS2 file system upload endpoint, which lacks authentication controls. The MPFS2 module normally provides read-only file system capabilities stored in external EEPROM, serial flash, or internal program memory for the HTTP2 web server and SNMP modules. However, the exposed upload endpoint allows attackers to write arbitrary binary images, overwriting the flash program memory that contains the web server's main interfaces. This enables code execution within the transmitter's embedded system. The attack is network-accessible without credentials, requires no user interaction, and affects all versions of 24 distinct transmitter products spanning DAB, FM, and TV broadcast equipment.

Defensive priority

HIGH

Recommended defensive actions

  • Contact Electrolink directly for security updates or mitigation guidance, as the vendor has not coordinated with CISA on fixes
  • Restrict network access to affected transmitter management interfaces using firewall rules or network segmentation
  • Monitor for unauthorized MPFS upload attempts to the unprotected endpoint
  • Implement defense-in-depth controls per CISA ICS recommended practices for industrial control systems
  • Consider disabling remote management interfaces if not operationally required
  • Review and apply CISA ICS-CERT defense in depth guidance for protecting critical broadcast infrastructure

Evidence notes

Vulnerability description and affected product list derived from CISA ICS Advisory ICSA-24-107-02. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N confirms network-exploitable, unauthenticated attack with high integrity impact. Vendor non-response status documented in advisory remediations section.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-1491 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-1491

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-1491 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-1491

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-107-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.