Back to Database
Status published
High
CVE-2024-3742
Electrolink FM/DAB/TV Transmitter Cleartext Storage of Sensitive Information
Vulnerability Description
Electrolink transmitters store credentials in clear-text. Use of these credentials could allow an attacker to access the system.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-3742
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Gjoko Krstic publicly reported these vulnerabilities on the internet after an unsuccessful attempt to contact Electrolink directly.
More from Electrolink
View All →CVE-2024-3741
Electrolink FM/DAB/TV Transmitter Authentication Bypass by Assumed-Immutable Data
High
8.7
CVE-2024-22186
Electrolink FM/DAB/TV Transmitter Reliance on Cookies without Validation and Integrity Checking
High
8.7
CVE-2024-22179
Electrolink FM/DAB/TV Transmitter Authentication Bypass by Assumed-Immutable Data
High
8.7
CVE-2024-21872
Electrolink FM/DAB/TV Transmitter Reliance on Cookies without Validation and Integrity Checking
High
8.7
CVE-2024-21846
Electrolink FM/DAB/TV Transmitter Missing Authentication for Critical Function
Medium
6.9
Affected Vendor
Electrolink
View all reports →Affected Software
Compact DAB Transmitter, Medium DAB Transmitter, High Power DAB Transmitter, Compact FM Transmitter, Modular FM Transmitter, Digital FM Transmitter, VHF TV Transmitter, UHF TV Transmitter
Vulnerable Versions:
10W, 100W, 250W, 500W, 1kW, 2kW, 2.5kW, 3kW, 4kW, 5kW, Compact FM Transmitter, 10kW, 15kW, 20kW, 30kW, 15W, BI, BIII
Timeline
Official Publish:
April 18th, 2024
Last Modified:
August 1st, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N