PatchSiren cyber security CVE debrief
CVE-2024-22186 Electrolink CVE debrief
CVE-2024-22186 is a HIGH severity (CVSS 8.8) privilege escalation vulnerability in Electrolink FM/DAB/TV transmitters, published 2024-04-16. An attacker with guest-level access can escalate to administrator privileges by manipulating session cookies. The vulnerability affects 24 Electrolink transmitter products across DAB, FM, and TV broadcast lines, with all versions impacted. Electrolink has not responded to CISA coordination requests, leaving no vendor patch available. Organizations should implement network segmentation, restrict transmitter web interface access to trusted management networks, and monitor for unauthorized privilege escalation attempts.
- Vendor
- Electrolink
- Product
- 10W Compact DAB Transmitter
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-16
- Original CVE updated
- 2024-04-16
- Advisory published
- 2024-04-16
- Advisory updated
- 2024-04-16
Who should care
Broadcast station engineers, critical infrastructure operators, media organizations, and ICS security teams managing over-the-air transmission equipment should prioritize assessment given the HIGH severity and lack of vendor remediation.
Technical summary
The Electrolink transmitter web application fails to properly validate session cookies, allowing a low-privileged guest user to modify cookie values and escalate to administrative privileges. This represents a broken access control vulnerability (CWE-269) with network attack vector, low attack complexity, and low privileges required. The CVSS 3.1 score of 8.8 reflects high impacts to confidentiality, integrity, and availability. All 24 affected transmitter products use the same vulnerable web management interface across DAB, FM, and TV broadcast product lines. No firmware update or patch is available from the vendor as of advisory publication.
Defensive priority
HIGH
Recommended defensive actions
- Restrict web management interface access to dedicated, segmented management networks with IP allowlisting
- Implement TLS inspection and cookie integrity monitoring for transmitter management sessions
- Deploy network monitoring to detect anomalous privilege escalation patterns from guest accounts
- Contact Electrolink directly for security updates given vendor non-response to CISA coordination
- Apply CISA ICS recommended practices for defense-in-depth in broadcast infrastructure environments
Evidence notes
CISA ICS Advisory ICSA-24-107-02 documents this vulnerability with CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The advisory confirms Electrolink's non-response to mitigation coordination. Affected products span 24 transmitter models including 10W-5kW DAB, 100W-30kW FM, and VHF/UHF TV transmitters.
Official resources
-
CVE-2024-22186 CVE record
CVE.org
-
CVE-2024-22186 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-04-16