This content is restricted.
Brief
Summary:
A vulnerability report from CISA (Cybersecurity and Infrastructure Security Agency) has identified multiple vulnerabilities in Sielco's Analog FM Transmitters and Radio Link devices. The report highlights the following:
Three vulnerabilities have been identified: Improper Access Control, Cross-Site Request Forgery, and Privilege Defined with Unsafe Actions.
The vulnerabilities have been assigned CVE numbers: CVE-2023-42769, CVE-2023-45317, CVE-2023-45228, and CVE-2023-41966.
CVSS v3.1 base scores for the vulnerabilities range from 6.5 to 9.8, indicating high to critical severity.
The affected devices and versions are listed in Section 3.1.
The report provides mitigation guidance, including minimizing network exposure, locating devices behind firewalls, exercising principles of least privilege, and implementing defensive measures.
CISA recommends organizations implement recommended cybersecurity strategies for proactive defense of ICS assets and report suspected malicious activity to CISA.
Recommendation: For users of affected versions of Sielco PolyEco FM Transmitter, contact Sielco customer support for additional information. Implement defensive measures to minimize the risk of exploitation of these vulnerabilities.
Highlights content goes here...
This content is restricted.
