PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-22186 Electrolink CVE debrief

CVE-2024-22186 is a HIGH severity (CVSS 8.8) privilege escalation vulnerability in Electrolink FM/DAB/TV transmitters, published 2024-04-16. An attacker with guest-level access can escalate to administrator privileges by manipulating session cookies. The vulnerability affects 24 Electrolink transmitter products across DAB, FM, and TV broadcast lines, with all versions impacted. Electrolink has not responded to CISA coordination requests, leaving no vendor patch available. Organizations should implement network segmentation, restrict transmitter web interface access to trusted management networks, and monitor for unauthorized privilege escalation attempts.

Vendor
Electrolink
Product
10W Compact DAB Transmitter
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-16
Original CVE updated
2024-04-16
Advisory published
2024-04-16
Advisory updated
2024-04-16

Who should care

Broadcast station engineers, critical infrastructure operators, media organizations, and ICS security teams managing over-the-air transmission equipment should prioritize assessment given the HIGH severity and lack of vendor remediation.

Technical summary

The Electrolink transmitter web application fails to properly validate session cookies, allowing a low-privileged guest user to modify cookie values and escalate to administrative privileges. This represents a broken access control vulnerability (CWE-269) with network attack vector, low attack complexity, and low privileges required. The CVSS 3.1 score of 8.8 reflects high impacts to confidentiality, integrity, and availability. All 24 affected transmitter products use the same vulnerable web management interface across DAB, FM, and TV broadcast product lines. No firmware update or patch is available from the vendor as of advisory publication.

Defensive priority

HIGH

Recommended defensive actions

  • Restrict web management interface access to dedicated, segmented management networks with IP allowlisting
  • Implement TLS inspection and cookie integrity monitoring for transmitter management sessions
  • Deploy network monitoring to detect anomalous privilege escalation patterns from guest accounts
  • Contact Electrolink directly for security updates given vendor non-response to CISA coordination
  • Apply CISA ICS recommended practices for defense-in-depth in broadcast infrastructure environments

Evidence notes

CISA ICS Advisory ICSA-24-107-02 documents this vulnerability with CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The advisory confirms Electrolink's non-response to mitigation coordination. Affected products span 24 transmitter models including 10W-5kW DAB, 100W-30kW FM, and VHF/UHF TV transmitters.

Official resources

2024-04-16