PatchSiren cyber security CVE debrief
CVE-2024-39375 marKoni CVE debrief
A critical authentication bypass vulnerability in TELSAT marKoni FM Transmitters allows remote attackers to gain administrator privileges without credentials. The flaw affects Markoni-D (Compact) and Markoni-DH (Exciter+Amplifiers) FM Transmitters running versions prior to 2.0.1. CISA published this advisory on June 27, 2024, with a CVSS 3.1 score of 9.8 (Critical). The vendor has released firmware version 2.0.1 to address the vulnerability. Organizations operating these broadcast transmission systems should prioritize patching due to the network-attack vector and complete compromise impact (confidentiality, integrity, and availability).
- Vendor
- marKoni
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-06-27
- Original CVE updated
- 2024-06-27
- Advisory published
- 2024-06-27
- Advisory updated
- 2024-06-27
Who should care
Broadcast media organizations, radio station operators, telecommunications providers, and critical infrastructure entities operating FM transmission equipment. Security teams managing industrial control systems in media and communications sectors should prioritize this patch due to the critical severity and remote exploitability.
Technical summary
The vulnerability exists in the authentication mechanism of TELSAT marKoni FM Transmitter management interfaces. An unauthenticated remote attacker can bypass authentication controls and obtain administrative privileges on the device. This grants full control over transmitter configuration and operation, with impacts spanning confidentiality, integrity, and availability of broadcast services. The attack requires no user interaction and can be executed over the network. Firmware version 2.0.1 remediates the authentication bypass flaw.
Defensive priority
critical
Recommended defensive actions
- Upgrade marKoni Markoni-D (Compact) and Markoni-DH (Exciter+Amplifiers) FM Transmitters to firmware version 2.0.1 or later.
- Contact Markoni directly for patch availability and installation guidance if not already on supported version.
- Restrict network access to FM transmitter management interfaces to authorized administrative hosts only.
- Monitor for unauthorized configuration changes or unexpected administrative sessions on affected devices.
- Apply defense-in-depth controls per CISA ICS recommended practices for industrial control systems.
Evidence notes
CISA CSAF advisory ICSA-24-179-01 confirms authentication bypass leading to admin privilege acquisition. Affected products explicitly listed as marKoni Markoni-D (Compact) FM Transmitters and Markoni-DH (Exciter+Amplifiers) FM Transmitters with fixed version 2.0.1. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H supports critical severity rating.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-39375 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-39375
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-39375 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-39375
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-179-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-179-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.