PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-22186 Electrolink CVE debrief

CVE-2024-22186 is a HIGH severity (CVSS 8.8) privilege escalation vulnerability in Electrolink FM/DAB/TV transmitters, published 2024-04-16. An attacker with guest-level access can escalate to administrator privileges by manipulating session cookies. The vulnerability affects 24 Electrolink transmitter products across DAB, FM, and TV broadcast lines, with all versions impacted. Electrolink has not responded to CISA coordination requests, leaving no vendor patch available. Organizations should implement network segmentation, restrict transmitter web interface access to trusted management networks, and monitor for unauthorized privilege escalation attempts.

Vendor
Electrolink
Product
10W Compact DAB Transmitter
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-16
Original CVE updated
2024-04-16
Advisory published
2024-04-16
Advisory updated
2024-04-16

Who should care

Broadcast station engineers, critical infrastructure operators, media organizations, and ICS security teams managing over-the-air transmission equipment should prioritize assessment given the HIGH severity and lack of vendor remediation.

Technical summary

The Electrolink transmitter web application fails to properly validate session cookies, allowing a low-privileged guest user to modify cookie values and escalate to administrative privileges. This represents a broken access control vulnerability (CWE-269) with network attack vector, low attack complexity, and low privileges required. The CVSS 3.1 score of 8.8 reflects high impacts to confidentiality, integrity, and availability. All 24 affected transmitter products use the same vulnerable web management interface across DAB, FM, and TV broadcast product lines. No firmware update or patch is available from the vendor as of advisory publication.

Defensive priority

HIGH

Recommended defensive actions

  • Restrict web management interface access to dedicated, segmented management networks with IP allowlisting
  • Implement TLS inspection and cookie integrity monitoring for transmitter management sessions
  • Deploy network monitoring to detect anomalous privilege escalation patterns from guest accounts
  • Contact Electrolink directly for security updates given vendor non-response to CISA coordination
  • Apply CISA ICS recommended practices for defense-in-depth in broadcast infrastructure environments

Evidence notes

CISA ICS Advisory ICSA-24-107-02 documents this vulnerability with CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The advisory confirms Electrolink's non-response to mitigation coordination. Affected products span 24 transmitter models including 10W-5kW DAB, 100W-30kW FM, and VHF/UHF TV transmitters.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-22186 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-22186

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-22186 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-22186

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-107-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.