PatchSiren cyber security CVE debrief
CVE-2024-3742 Electrolink CVE debrief
CISA published advisory ICSA-24-107-02 on April 16, 2024, disclosing that Electrolink FM/DAB/TV transmitters store credentials in clear-text. The vulnerability affects 24 product variants spanning DAB, FM, and TV transmitter lines. An attacker with network access could use these exposed credentials to gain unauthorized system access. Electrolink has not responded to CISA's coordination requests, and no vendor patch is currently available. The affected products are deployed in broadcast infrastructure environments where compromise could disrupt radio and television transmission services.
- Vendor
- Electrolink
- Product
- 10W Compact DAB Transmitter
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-16
- Original CVE updated
- 2024-04-16
- Advisory published
- 2024-04-16
- Advisory updated
- 2024-04-16
Who should care
Broadcast station engineers, critical infrastructure operators, media companies, telecommunications regulators, and security teams responsible for broadcast transmission infrastructure should prioritize assessment of Electrolink deployments in their environments.
Technical summary
The vulnerability exists in the credential storage mechanism of Electrolink broadcast transmitters. Credentials are stored without encryption or hashing, exposing them to any attacker who can access the stored data. With network access to the device, an attacker could retrieve these credentials and authenticate to the transmitter's management interface. The CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N indicates network attack vector, low attack complexity, no privileges required, no user interaction, and high confidentiality impact. The 24 affected products cover the complete Electrolink transmitter portfolio across DAB, FM, and VHF/UHF TV broadcast bands.
Defensive priority
HIGH
Recommended defensive actions
- Contact Electrolink directly for security guidance and potential firmware updates
- Segment transmitter management interfaces from operational networks and untrusted zones
- Implement strong network access controls limiting management plane exposure
- Audit and rotate any credentials that may have been exposed through clear-text storage
- Monitor for unauthorized access attempts to transmitter management interfaces
- Apply CISA ICS recommended practices for defense-in-depth architecture
- Review backup and recovery procedures for broadcast transmission systems
Evidence notes
CISA advisory ICSA-24-107-02 documents clear-text credential storage across 24 Electrolink transmitter products. CVSS 3.1 score of 7.5 reflects network exploitable, low complexity, no privileges required, with high confidentiality impact. Vendor non-response confirmed in remediation section.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-3742 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-3742
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-3742 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-3742
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-107-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.