PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-39374 marKoni CVE debrief

TELSAT marKoni FM Transmitters contain a critical vulnerability (CVSS 9.8) in which a hidden administrative account is protected by hard-coded credentials, allowing unauthenticated remote attackers to gain full administrative control. The vulnerability affects Markoni-D (Compact) and Markoni-DH (Exciter+Amplifiers) FM Transmitters prior to version 2.0.1. Because these devices are network-accessible broadcast infrastructure components, exploitation could enable attackers to disrupt radio transmission operations, reconfigure transmitter settings, or pivot into connected broadcast networks. The issue was disclosed by CISA on June 27, 2024, with a patched firmware version available from the vendor.

Vendor
marKoni
Product
Unknown
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-06-27
Original CVE updated
2024-06-27
Advisory published
2024-06-27
Advisory updated
2024-06-27

Who should care

Broadcast station engineers, critical infrastructure security teams, media organizations operating FM transmission equipment, and OT security practitioners responsible for radio broadcast networks

Technical summary

The vulnerability exists due to hard-coded credentials protecting a hidden administrative account in marKoni FM Transmitter firmware. Attackers with network access to the device can authenticate using these static credentials without prior knowledge of legitimate accounts, obtaining complete administrative control over transmitter configuration and operations. The attack requires no user interaction and can be executed remotely. Affected products include Markoni-D (Compact) FM Transmitters and Markoni-DH (Exciter+Amplifiers) FM Transmitters running firmware versions prior to 2.0.1.

Defensive priority

critical

Recommended defensive actions

  • Upgrade affected marKoni Markoni-D and Markoni-DH FM Transmitters to firmware version 2.0.1 or later
  • Restrict network access to transmitter management interfaces using firewall rules or network segmentation
  • Audit device configurations for unauthorized administrative access or configuration changes
  • Monitor network traffic for unexpected connections to transmitter management ports
  • Contact marKoni technical support for additional hardening guidance if vendor contact is required

Evidence notes

CISA ICS advisory ICSA-24-179-01 confirms hard-coded credentials in a hidden admin account affecting marKoni FM Transmitters. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H supports critical severity. Remediation guidance specifies firmware version 2.0.1 as the fixed release.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-39374 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-39374

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-39374 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-39374

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-179-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-179-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.