CVE Published: 18/04/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: icscert |
Vendor: Electrolink |
Product: Compact DAB Transmitter Status : PUBLISHED
CVE-2024-3741 Description
Electrolink transmitters are vulnerable to an authentication bypass
vulnerability affecting the login cookie. An attacker can set an
arbitrary value except \'NO\' to the login cookie and have full system
access.
Metrics
CVSS Version: 3.1 |
Base Score: 7.5 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N