This content is restricted.
Brief
Summary:
The document is a View CSAF (Common Vulnerability Scoring System Architecture Framework) report that outlines four security vulnerabilities affecting Electrolink's FM/DAB/TV Transmitter equipment. The vulnerabilities are:
1. Authentication Bypass by Assumed-Immutable Data (CVSS v3: 8.8)
2. Reliance on Cookies without Validation and Integrity Checking (CVSS v3: 8.8)
3. Missing Authentication for Critical Function (CVSS v3: 7.5)
4. Cleartext Storage of Sensitive Information (CVSS v3: 7.5)
These vulnerabilities can allow an attacker to gain full system access, stop the device from transmitting, escalate privileges, change credentials, and execute arbitrary code. The report provides information on the affected products, technical details, and recommendations for mitigation.
Mitigations:
The report recommends minimizing network exposure, locating control systems behind firewalls, and using secure remote access methods. It also encourages organizations to perform proper impact analysis and risk assessments prior to deploying defensive measures.
Update History:
The report was initially published on April 16, 2024.
Highlights content goes here...
This content is restricted.