PatchSiren cyber security CVE debrief
CVE-2024-22186 Electrolink CVE debrief
CVE-2024-22186 is a HIGH severity (CVSS 8.8) privilege escalation vulnerability in Electrolink FM/DAB/TV transmitters, published 2024-04-16. An attacker with guest-level access can escalate to administrator privileges by manipulating session cookies. The vulnerability affects 24 Electrolink transmitter products across DAB, FM, and TV broadcast lines, with all versions impacted. Electrolink has not responded to CISA coordination requests, leaving no vendor patch available. Organizations should implement network segmentation, restrict transmitter web interface access to trusted management networks, and monitor for unauthorized privilege escalation attempts.
- Vendor
- Electrolink
- Product
- 10W Compact DAB Transmitter
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-16
- Original CVE updated
- 2024-04-16
- Advisory published
- 2024-04-16
- Advisory updated
- 2024-04-16
Who should care
Broadcast station engineers, critical infrastructure operators, media organizations, and ICS security teams managing over-the-air transmission equipment should prioritize assessment given the HIGH severity and lack of vendor remediation.
Technical summary
The Electrolink transmitter web application fails to properly validate session cookies, allowing a low-privileged guest user to modify cookie values and escalate to administrative privileges. This represents a broken access control vulnerability (CWE-269) with network attack vector, low attack complexity, and low privileges required. The CVSS 3.1 score of 8.8 reflects high impacts to confidentiality, integrity, and availability. All 24 affected transmitter products use the same vulnerable web management interface across DAB, FM, and TV broadcast product lines. No firmware update or patch is available from the vendor as of advisory publication.
Defensive priority
HIGH
Recommended defensive actions
- Restrict web management interface access to dedicated, segmented management networks with IP allowlisting
- Implement TLS inspection and cookie integrity monitoring for transmitter management sessions
- Deploy network monitoring to detect anomalous privilege escalation patterns from guest accounts
- Contact Electrolink directly for security updates given vendor non-response to CISA coordination
- Apply CISA ICS recommended practices for defense-in-depth in broadcast infrastructure environments
Evidence notes
CISA ICS Advisory ICSA-24-107-02 documents this vulnerability with CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The advisory confirms Electrolink's non-response to mitigation coordination. Affected products span 24 transmitter models including 10W-5kW DAB, 100W-30kW FM, and VHF/UHF TV transmitters.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-22186 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-22186
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-22186 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-22186
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-107-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.