Lucene search

K
cvelistIcscertCVELIST:CVE-2024-3742
HistoryApr 18, 2024 - 10:15 p.m.

CVE-2024-3742 Electrolink FM/DAB/TV Transmitter Cleartext Storage of Sensitive Information

2024-04-1822:15:35
CWE-312
icscert
www.cve.org
2
cve-2024-3742
electrolink
transmitter
credential
storage
clear-text
sensitive
information
attacker
access

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS4

8.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:N/SI:N/VA:N/SA:N

EPSS

0.001

Percentile

22.1%

Electrolink transmitters store credentials in clear-text. Use of these credentials could allow an attacker to access the system.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Compact DAB Transmitter",
    "vendor": "Electrolink",
    "versions": [
      {
        "status": "affected",
        "version": "10W"
      },
      {
        "status": "affected",
        "version": "100W"
      },
      {
        "status": "affected",
        "version": "250W"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Medium DAB Transmitter",
    "vendor": "Electrolink",
    "versions": [
      {
        "status": "affected",
        "version": "500W"
      },
      {
        "status": "affected",
        "version": "1kW"
      },
      {
        "status": "affected",
        "version": "2kW"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "High Power DAB Transmitter",
    "vendor": "Electrolink",
    "versions": [
      {
        "status": "affected",
        "version": "2.5kW"
      },
      {
        "status": "affected",
        "version": "3kW"
      },
      {
        "status": "affected",
        "version": "4kW"
      },
      {
        "status": "affected",
        "version": "5kW"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Compact FM Transmitter",
    "vendor": "Electrolink",
    "versions": [
      {
        "status": "affected",
        "version": "Compact FM Transmitter"
      },
      {
        "status": "affected",
        "version": "500W"
      },
      {
        "status": "affected",
        "version": "1kW"
      },
      {
        "status": "affected",
        "version": "2kW"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Modular FM Transmitter",
    "vendor": "Electrolink",
    "versions": [
      {
        "status": "affected",
        "version": "3kW"
      },
      {
        "status": "affected",
        "version": "5kW"
      },
      {
        "status": "affected",
        "version": "10kW"
      },
      {
        "status": "affected",
        "version": "15kW"
      },
      {
        "status": "affected",
        "version": "20kW"
      },
      {
        "status": "affected",
        "version": "30kW"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Digital FM Transmitter",
    "vendor": "Electrolink",
    "versions": [
      {
        "lessThanOrEqual": "40kW",
        "status": "affected",
        "version": "15W",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "VHF TV Transmitter",
    "vendor": "Electrolink",
    "versions": [
      {
        "status": "affected",
        "version": "BI"
      },
      {
        "status": "affected",
        "version": "BIII"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "UHF TV Transmitter",
    "vendor": "Electrolink",
    "versions": [
      {
        "lessThanOrEqual": "5kW",
        "status": "affected",
        "version": "10W",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS4

8.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:N/SI:N/VA:N/SA:N

EPSS

0.001

Percentile

22.1%

Related for CVELIST:CVE-2024-3742