PatchSiren cyber security CVE debrief
CVE-2024-21872 Electrolink CVE debrief
CVE-2024-21872 is a HIGH severity (CVSS 7.5) authentication bypass vulnerability affecting 24 Electrolink FM/DAB/TV transmitter models. Published 2024-04-16 by CISA, this flaw allows unauthenticated attackers to bypass authentication by modifying cookies to access hidden administrative pages and perform critical transmitter operations. The vulnerability impacts broadcast infrastructure across DAB, FM, and TV transmitter product lines with all versions affected. Electrolink has not responded to CISA coordination requests, leaving users without vendor patches. Immediate defensive measures include network segmentation, access controls, and monitoring for unauthorized cookie manipulation attempts.
- Vendor
- Electrolink
- Product
- 10W Compact DAB Transmitter
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-16
- Original CVE updated
- 2024-04-16
- Advisory published
- 2024-04-16
- Advisory updated
- 2024-04-16
Who should care
Broadcast operators, critical infrastructure defenders, and OT security teams managing Electrolink FM/DAB/TV transmitters should prioritize assessment and network segmentation given the unpatched status and critical operational impact potential.
Technical summary
The Electrolink transmitter web interface contains an authentication bypass vulnerability where cookie values can be modified by unauthenticated attackers to reveal hidden administrative pages. This grants access to critical transmitter operations without valid credentials. The flaw affects all versions of 24 transmitter models across DAB, FM, and TV product lines. No vendor patch is available as Electrolink has not engaged with CISA coordination efforts.
Defensive priority
critical
Recommended defensive actions
- Segment Electrolink transmitter management interfaces from operational networks and untrusted access
- Implement strict network access controls limiting web interface access to authorized management stations only
- Monitor for anomalous cookie values or unexpected administrative page access attempts
- Contact Electrolink directly for security updates given vendor non-response to CISA coordination
- Apply CISA ICS recommended practices for defense-in-depth in industrial control environments
- Consider out-of-band management alternatives where web interface exposure cannot be eliminated
Evidence notes
CISA ICS Advisory ICSA-24-107-02 documents this vulnerability with CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The advisory confirms Electrolink's non-response to mitigation coordination. Affected products span 24 transmitter models across DAB (10W–5kW), FM (100W–40kW), and TV (VHF/UHF) product families.
Official resources
-
CVE-2024-21872 CVE record
CVE.org
-
CVE-2024-21872 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-04-16