PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-39375 marKoni CVE debrief

A critical authentication bypass vulnerability in TELSAT marKoni FM Transmitters allows remote attackers to gain administrator privileges without credentials. The flaw affects Markoni-D (Compact) and Markoni-DH (Exciter+Amplifiers) FM Transmitters running versions prior to 2.0.1. CISA published this advisory on June 27, 2024, with a CVSS 3.1 score of 9.8 (Critical). The vendor has released firmware version 2.0.1 to address the vulnerability. Organizations operating these broadcast transmission systems should prioritize patching due to the network-attack vector and complete compromise impact (confidentiality, integrity, and availability).

Vendor
marKoni
Product
Unknown
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-06-27
Original CVE updated
2024-06-27
Advisory published
2024-06-27
Advisory updated
2024-06-27

Who should care

Broadcast media organizations, radio station operators, telecommunications providers, and critical infrastructure entities operating FM transmission equipment. Security teams managing industrial control systems in media and communications sectors should prioritize this patch due to the critical severity and remote exploitability.

Technical summary

The vulnerability exists in the authentication mechanism of TELSAT marKoni FM Transmitter management interfaces. An unauthenticated remote attacker can bypass authentication controls and obtain administrative privileges on the device. This grants full control over transmitter configuration and operation, with impacts spanning confidentiality, integrity, and availability of broadcast services. The attack requires no user interaction and can be executed over the network. Firmware version 2.0.1 remediates the authentication bypass flaw.

Defensive priority

critical

Recommended defensive actions

  • Upgrade marKoni Markoni-D (Compact) and Markoni-DH (Exciter+Amplifiers) FM Transmitters to firmware version 2.0.1 or later.
  • Contact Markoni directly for patch availability and installation guidance if not already on supported version.
  • Restrict network access to FM transmitter management interfaces to authorized administrative hosts only.
  • Monitor for unauthorized configuration changes or unexpected administrative sessions on affected devices.
  • Apply defense-in-depth controls per CISA ICS recommended practices for industrial control systems.

Evidence notes

CISA CSAF advisory ICSA-24-179-01 confirms authentication bypass leading to admin privilege acquisition. Affected products explicitly listed as marKoni Markoni-D (Compact) FM Transmitters and Markoni-DH (Exciter+Amplifiers) FM Transmitters with fixed version 2.0.1. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H supports critical severity rating.

Official resources

2024-06-27