CVE-2024-3742 describes a critical vulnerability in Electrolink transmitters where credentials are stored in clear-text, allowing unauthorized access to the system. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network without user interaction, leading to a complete compromise of confidentiality. While not currently in the KEV catalog, a Nuclei template exists for detecting this flaw, and despite its high FAUCET Risk Score, there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Electrolink | Compact DAB Transmitter | 100W, 10W, 250WCNA affecteddefault unaffected | |
| Electrolink | Compact FM Transmitter | 1kW, 2kW, 500W, Compact FM TransmitterCNA affecteddefault unaffected | |
| Electrolink | Digital FM Transmitter | >= 15W, <= 40kWCNA affecteddefault unaffected | |
| Electrolink | High Power DAB Transmitter | 2.5kW, 3kW, 4kW, 5kWCNA affecteddefault unaffected | |
| Electrolink | Medium DAB Transmitter | 1kW, 2kW, 500WCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.