Sielco Radio Link and Analog FM Transmitters

View CSAF

1. EXECUTIVE SUMMARY

  • CVSS v3 9.8
  • ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
  • Vendor: Sielco
  • Equipment: Analog FM Transmitters and Radio Link
  • Vulnerabilities: Improper Access Control, Cross-Site Request Forgery, Privilege Defined with Unsafe Actions

2. RISK EVALUATION

Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges, access restricted pages, or hijack sessions.

3. TECHNICAL DETAILS

3.1 AFFECTED PRODUCTS

The following Sielco devices are affected:

  • Analog FM transmitter: 2.12 (EXC5000GX)
  • Analog FM transmitter: 2.12 (EXC120GX)
  • Analog FM transmitter: 2.11 (EXC300GX)
  • Analog FM transmitter: 2.10 (EXC1600GX)
  • Analog FM transmitter: 2.10 (EXC2000GX)
  • Analog FM transmitter: 2.08 (EXC1600GX)
  • Analog FM transmitter: 2.08 (EXC1000GX)
  • Analog FM transmitter: 2.07 (EXC3000GX)
  • Analog FM transmitter: 2.06 (EXC5000GX)
  • Analog FM transmitter: 1.7.7 (EXC30GT)
  • Analog FM transmitter: 1.7.4 (EXC300GT)
  • Analog FM transmitter: 1.7.4 (EXC100GT)
  • Analog FM transmitter: 1.7.4 (EXC5000GT)
  • Analog FM transmitter: 1.6.3 (EXC1000GT)
  • Analog FM transmitter: 1.5.4 (EXC120GT)
  • Radio Link: 2.06 (RTX19)
  • Radio Link: 2.05 (RTX19)
  • Radio Link: 2.00 (EXC19)
  • Radio Link: 1.60 (RTX19)
  • Radio Link: 1.59 (RTX19)
  • Radio Link: 1.55 (EXC19)

3.2 Vulnerability Overview

3.2.1 Improper Access Control CWE-284

The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.

CVE-2023-42769 has been assigned to this vulnerability. A CVSS v3.1 base score of 9.8 has been calculated; the CVSS vec

[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.

This article has been indexed from All CISA Advisories

Read the original article: