Brief

Summary:

A vulnerability report from CISA (Cybersecurity and Infrastructure Security Agency) has identified multiple vulnerabilities in Sielco's Analog FM Transmitters and Radio Link devices. The report highlights the following:

Three vulnerabilities have been identified: Improper Access Control, Cross-Site Request Forgery, and Privilege Defined with Unsafe Actions.
The vulnerabilities have been assigned CVE numbers: CVE-2023-42769, CVE-2023-45317, CVE-2023-45228, and CVE-2023-41966.
CVSS v3.1 base scores for the vulnerabilities range from 6.5 to 9.8, indicating high to critical severity.
The affected devices and versions are listed in Section 3.1.
The report provides mitigation guidance, including minimizing network exposure, locating devices behind firewalls, exercising principles of least privilege, and implementing defensive measures.
CISA recommends organizations implement recommended cybersecurity strategies for proactive defense of ICS assets and report suspected malicious activity to CISA.

Recommendation: For users of affected versions of Sielco PolyEco FM Transmitter, contact Sielco customer support for additional information. Implement defensive measures to minimize the risk of exploitation of these vulnerabilities.

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable remotely/low attack complexity/public exploits are available Vendor: Sielco Equipment: Analog FM Transmitters and Radio Link Vulnerabilities: Improper Access Control, Cross-Site Request Forgery, Privilege Defined with Unsafe Actions 2. RISK EVALUATION Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges, access restricted pages

This content is restricted.

Highlights content goes here...

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable remotely/low attack complexity/public exploits are available Vendor: Sielco Equipment: Analog FM Transmitters and Radio Link Vulnerabilities: Improper Access Control, Cross-Site Request Forgery, Privilege Defined with Unsafe Actions 2. RISK EVALUATION Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges, access restricted pages

This content is restricted.

Cybersecurity and Infrastructure Security Agency

Quick Insight
RADA.AI
RADA.AI
Hello! I'm RADA.AI - Regulatory Analysis and Decision Assistance. Your Intelligent guide for compliance and decision-making. How can i assist you today?
Suggested

Form successfully submitted. One of our GRI rep will contact you shortly

Thanking You!

Enter your Email

Enter your registered username/email id.

Enter your Email

Enter your email id below to signup.
Individual Plan
$125 / month OR $1250 / year
Features
Best for: Researchers, Legal professionals, Academics
Enterprise Plan
Contact for Pricing
Features
Best for: Law Firms, Corporations, Government Bodies