Search

Find a vulnerability

Search criteria

    4 vulnerabilities by 0xacab

    CVE-2024-1491 (GCVE-0-2024-1491)

    Vulnerability from nvd – Published: 2024-04-18 22:13 – Updated: 2024-08-01 18:40
    VLAI
    Title
    Electrolink FM/DAB/TV Transmitter Missing Authentication for Critical Function
    Summary
    The devices allow access to an unprotected endpoint that allows MPFS file system binary image upload without authentication. The MPFS2 file system module provides a light-weight read-only file system that can be stored in external EEPROM, external serial flash, or internal flash program memory. This file system serves as the basis for the HTTP2 web server module, but is also used by the SNMP module and is available to other applications that require basic read-only storage capabilities. This can be exploited to overwrite the flash program memory that holds the web server's main interfaces and execute arbitrary code.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-04-23 00:25 UTC
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    Impacted products
    Vendor Product Version
    Electrolink Compact DAB Transmitter Affected: 10W
    Affected: 100W
    Affected: 250W
    Create a notification for this product.
    Electrolink Medium DAB Transmitter Affected: 500W
    Affected: 1kW
    Affected: 2kW
    Create a notification for this product.
    Electrolink High Power DAB Transmitter Affected: 2.5kW
    Affected: 3kW
    Affected: 4kW
    Affected: 5kW
    Create a notification for this product.
    Electrolink Compact FM Transmitter Affected: Compact FM Transmitter
    Affected: 500W
    Affected: 1kW
    Affected: 2kW
    Create a notification for this product.
    Electrolink Modular FM Transmitter Affected: 3kW
    Affected: 5kW
    Affected: 10kW
    Affected: 15kW
    Affected: 20kW
    Affected: 30kW
    Create a notification for this product.
    Electrolink Digital FM Transmitter Affected: 15W , ≤ 40kW (custom)
    Create a notification for this product.
    Electrolink VHF TV Transmitter Affected: BI
    Affected: BIII
    Create a notification for this product.
    Electrolink UHF TV Transmitter Affected: 10W , ≤ 5kW (custom)
    Create a notification for this product.
    0xacab mat2 Affected: 0.10.0
        cpe:2.3:a:0xacab:mat2:0.10.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:0xacab:mat2:0.10.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mat2",
                "vendor": "0xacab",
                "versions": [
                  {
                    "status": "affected",
                    "version": "0.10.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-1491",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-04-23T00:25:00.939738Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T18:01:37.950Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:40:21.285Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Compact DAB Transmitter",
              "vendor": "Electrolink",
              "versions": [
                {
                  "status": "affected",
                  "version": "10W"
                },
                {
                  "status": "affected",
                  "version": "100W"
                },
                {
                  "status": "affected",
                  "version": "250W"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Medium DAB Transmitter",
              "vendor": "Electrolink",
              "versions": [
                {
                  "status": "affected",
                  "version": "500W"
                },
                {
                  "status": "affected",
                  "version": "1kW"
                },
                {
                  "status": "affected",
                  "version": "2kW"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "High Power DAB Transmitter",
              "vendor": "Electrolink",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.5kW"
                },
                {
                  "status": "affected",
                  "version": "3kW"
                },
                {
                  "status": "affected",
                  "version": "4kW"
                },
                {
                  "status": "affected",
                  "version": "5kW"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Compact FM Transmitter",
              "vendor": "Electrolink",
              "versions": [
                {
                  "status": "affected",
                  "version": "Compact FM Transmitter"
                },
                {
                  "status": "affected",
                  "version": "500W"
                },
                {
                  "status": "affected",
                  "version": "1kW"
                },
                {
                  "status": "affected",
                  "version": "2kW"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Modular FM Transmitter",
              "vendor": "Electrolink",
              "versions": [
                {
                  "status": "affected",
                  "version": "3kW"
                },
                {
                  "status": "affected",
                  "version": "5kW"
                },
                {
                  "status": "affected",
                  "version": "10kW"
                },
                {
                  "status": "affected",
                  "version": "15kW"
                },
                {
                  "status": "affected",
                  "version": "20kW"
                },
                {
                  "status": "affected",
                  "version": "30kW"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Digital FM Transmitter",
              "vendor": "Electrolink",
              "versions": [
                {
                  "lessThanOrEqual": "40kW",
                  "status": "affected",
                  "version": "15W",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VHF TV Transmitter",
              "vendor": "Electrolink",
              "versions": [
                {
                  "status": "affected",
                  "version": "BI"
                },
                {
                  "status": "affected",
                  "version": "BIII"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UHF TV Transmitter",
              "vendor": "Electrolink",
              "versions": [
                {
                  "lessThanOrEqual": "5kW",
                  "status": "affected",
                  "version": "10W",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gjoko Krstic publicly reported these vulnerabilities on the internet after an unsuccessful attempt to contact Electrolink directly."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The devices allow access to an unprotected endpoint that allows MPFS \nfile system binary image upload without authentication. The MPFS2 file \nsystem module provides a light-weight read-only file system that can be \nstored in external EEPROM, external serial flash, or internal flash \nprogram memory. This file system serves as the basis for the HTTP2 web \nserver module, but is also used by the SNMP module and is available to \nother applications that require basic read-only storage capabilities. \nThis can be exploited to overwrite the flash program memory that holds \nthe web server\u0027s main interfaces and execute arbitrary code."
                }
              ],
              "value": "The devices allow access to an unprotected endpoint that allows MPFS \nfile system binary image upload without authentication. The MPFS2 file \nsystem module provides a light-weight read-only file system that can be \nstored in external EEPROM, external serial flash, or internal flash \nprogram memory. This file system serves as the basis for the HTTP2 web \nserver module, but is also used by the SNMP module and is available to \nother applications that require basic read-only storage capabilities. \nThis can be exploited to overwrite the flash program memory that holds \nthe web server\u0027s main interfaces and execute arbitrary code."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-05-28T16:51:09.051Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02"
            }
          ],
          "source": {
            "advisory": "ICSA-24-107-02",
            "discovery": "EXTERNAL"
          },
          "title": "Electrolink FM/DAB/TV Transmitter Missing Authentication for Critical Function",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Electrolink has not responded to requests to work with CISA to mitigate \nthese vulnerabilities. Users of the affected products are encouraged to \ncontact \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://electrolink.com/contacts/\"\u003eElectrolink\u003c/a\u003e for additional information.\n\n\u003cbr\u003e"
                }
              ],
              "value": "Electrolink has not responded to requests to work with CISA to mitigate \nthese vulnerabilities. Users of the affected products are encouraged to \ncontact  Electrolink https://electrolink.com/contacts/  for additional information."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2024-1491",
        "datePublished": "2024-04-18T22:13:54.962Z",
        "dateReserved": "2024-02-14T15:46:18.806Z",
        "dateUpdated": "2024-08-01T18:40:21.285Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-35410 (GCVE-0-2022-35410)

    Vulnerability from nvd – Published: 2022-07-08 17:35 – Updated: 2024-08-03 09:36
    VLAI
    Summary
    mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T09:36:44.366Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://0xacab.org/jvoisin/mat2/-/issues/174"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://0xacab.org/jvoisin/mat2/-/commit/beebca4bf1cd3b935824c966ce077e7bcf610385"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://dustri.org/b/mat2-0130.html"
              },
              {
                "name": "DSA-5185",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "https://www.debian.org/security/2022/dsa-5185"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-07-16T02:06:06.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://0xacab.org/jvoisin/mat2/-/issues/174"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://0xacab.org/jvoisin/mat2/-/commit/beebca4bf1cd3b935824c966ce077e7bcf610385"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://dustri.org/b/mat2-0130.html"
            },
            {
              "name": "DSA-5185",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "https://www.debian.org/security/2022/dsa-5185"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2022-35410",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://0xacab.org/jvoisin/mat2/-/issues/174",
                  "refsource": "MISC",
                  "url": "https://0xacab.org/jvoisin/mat2/-/issues/174"
                },
                {
                  "name": "https://0xacab.org/jvoisin/mat2/-/commit/beebca4bf1cd3b935824c966ce077e7bcf610385",
                  "refsource": "MISC",
                  "url": "https://0xacab.org/jvoisin/mat2/-/commit/beebca4bf1cd3b935824c966ce077e7bcf610385"
                },
                {
                  "name": "https://dustri.org/b/mat2-0130.html",
                  "refsource": "MISC",
                  "url": "https://dustri.org/b/mat2-0130.html"
                },
                {
                  "name": "DSA-5185",
                  "refsource": "DEBIAN",
                  "url": "https://www.debian.org/security/2022/dsa-5185"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2022-35410",
        "datePublished": "2022-07-08T17:35:23.000Z",
        "dateReserved": "2022-07-08T00:00:00.000Z",
        "dateUpdated": "2024-08-03T09:36:44.366Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-1491 (GCVE-0-2024-1491)

    Vulnerability from cvelistv5 – Published: 2024-04-18 22:13 – Updated: 2024-08-01 18:40
    VLAI
    Title
    Electrolink FM/DAB/TV Transmitter Missing Authentication for Critical Function
    Summary
    The devices allow access to an unprotected endpoint that allows MPFS file system binary image upload without authentication. The MPFS2 file system module provides a light-weight read-only file system that can be stored in external EEPROM, external serial flash, or internal flash program memory. This file system serves as the basis for the HTTP2 web server module, but is also used by the SNMP module and is available to other applications that require basic read-only storage capabilities. This can be exploited to overwrite the flash program memory that holds the web server's main interfaces and execute arbitrary code.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-04-23 00:25 UTC
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    Impacted products
    Vendor Product Version
    Electrolink Compact DAB Transmitter Affected: 10W
    Affected: 100W
    Affected: 250W
    Create a notification for this product.
    Electrolink Medium DAB Transmitter Affected: 500W
    Affected: 1kW
    Affected: 2kW
    Create a notification for this product.
    Electrolink High Power DAB Transmitter Affected: 2.5kW
    Affected: 3kW
    Affected: 4kW
    Affected: 5kW
    Create a notification for this product.
    Electrolink Compact FM Transmitter Affected: Compact FM Transmitter
    Affected: 500W
    Affected: 1kW
    Affected: 2kW
    Create a notification for this product.
    Electrolink Modular FM Transmitter Affected: 3kW
    Affected: 5kW
    Affected: 10kW
    Affected: 15kW
    Affected: 20kW
    Affected: 30kW
    Create a notification for this product.
    Electrolink Digital FM Transmitter Affected: 15W , ≤ 40kW (custom)
    Create a notification for this product.
    Electrolink VHF TV Transmitter Affected: BI
    Affected: BIII
    Create a notification for this product.
    Electrolink UHF TV Transmitter Affected: 10W , ≤ 5kW (custom)
    Create a notification for this product.
    0xacab mat2 Affected: 0.10.0
        cpe:2.3:a:0xacab:mat2:0.10.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:0xacab:mat2:0.10.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mat2",
                "vendor": "0xacab",
                "versions": [
                  {
                    "status": "affected",
                    "version": "0.10.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-1491",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-04-23T00:25:00.939738Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T18:01:37.950Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:40:21.285Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Compact DAB Transmitter",
              "vendor": "Electrolink",
              "versions": [
                {
                  "status": "affected",
                  "version": "10W"
                },
                {
                  "status": "affected",
                  "version": "100W"
                },
                {
                  "status": "affected",
                  "version": "250W"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Medium DAB Transmitter",
              "vendor": "Electrolink",
              "versions": [
                {
                  "status": "affected",
                  "version": "500W"
                },
                {
                  "status": "affected",
                  "version": "1kW"
                },
                {
                  "status": "affected",
                  "version": "2kW"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "High Power DAB Transmitter",
              "vendor": "Electrolink",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.5kW"
                },
                {
                  "status": "affected",
                  "version": "3kW"
                },
                {
                  "status": "affected",
                  "version": "4kW"
                },
                {
                  "status": "affected",
                  "version": "5kW"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Compact FM Transmitter",
              "vendor": "Electrolink",
              "versions": [
                {
                  "status": "affected",
                  "version": "Compact FM Transmitter"
                },
                {
                  "status": "affected",
                  "version": "500W"
                },
                {
                  "status": "affected",
                  "version": "1kW"
                },
                {
                  "status": "affected",
                  "version": "2kW"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Modular FM Transmitter",
              "vendor": "Electrolink",
              "versions": [
                {
                  "status": "affected",
                  "version": "3kW"
                },
                {
                  "status": "affected",
                  "version": "5kW"
                },
                {
                  "status": "affected",
                  "version": "10kW"
                },
                {
                  "status": "affected",
                  "version": "15kW"
                },
                {
                  "status": "affected",
                  "version": "20kW"
                },
                {
                  "status": "affected",
                  "version": "30kW"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Digital FM Transmitter",
              "vendor": "Electrolink",
              "versions": [
                {
                  "lessThanOrEqual": "40kW",
                  "status": "affected",
                  "version": "15W",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VHF TV Transmitter",
              "vendor": "Electrolink",
              "versions": [
                {
                  "status": "affected",
                  "version": "BI"
                },
                {
                  "status": "affected",
                  "version": "BIII"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "UHF TV Transmitter",
              "vendor": "Electrolink",
              "versions": [
                {
                  "lessThanOrEqual": "5kW",
                  "status": "affected",
                  "version": "10W",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gjoko Krstic publicly reported these vulnerabilities on the internet after an unsuccessful attempt to contact Electrolink directly."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The devices allow access to an unprotected endpoint that allows MPFS \nfile system binary image upload without authentication. The MPFS2 file \nsystem module provides a light-weight read-only file system that can be \nstored in external EEPROM, external serial flash, or internal flash \nprogram memory. This file system serves as the basis for the HTTP2 web \nserver module, but is also used by the SNMP module and is available to \nother applications that require basic read-only storage capabilities. \nThis can be exploited to overwrite the flash program memory that holds \nthe web server\u0027s main interfaces and execute arbitrary code."
                }
              ],
              "value": "The devices allow access to an unprotected endpoint that allows MPFS \nfile system binary image upload without authentication. The MPFS2 file \nsystem module provides a light-weight read-only file system that can be \nstored in external EEPROM, external serial flash, or internal flash \nprogram memory. This file system serves as the basis for the HTTP2 web \nserver module, but is also used by the SNMP module and is available to \nother applications that require basic read-only storage capabilities. \nThis can be exploited to overwrite the flash program memory that holds \nthe web server\u0027s main interfaces and execute arbitrary code."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-05-28T16:51:09.051Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02"
            }
          ],
          "source": {
            "advisory": "ICSA-24-107-02",
            "discovery": "EXTERNAL"
          },
          "title": "Electrolink FM/DAB/TV Transmitter Missing Authentication for Critical Function",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Electrolink has not responded to requests to work with CISA to mitigate \nthese vulnerabilities. Users of the affected products are encouraged to \ncontact \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://electrolink.com/contacts/\"\u003eElectrolink\u003c/a\u003e for additional information.\n\n\u003cbr\u003e"
                }
              ],
              "value": "Electrolink has not responded to requests to work with CISA to mitigate \nthese vulnerabilities. Users of the affected products are encouraged to \ncontact  Electrolink https://electrolink.com/contacts/  for additional information."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2024-1491",
        "datePublished": "2024-04-18T22:13:54.962Z",
        "dateReserved": "2024-02-14T15:46:18.806Z",
        "dateUpdated": "2024-08-01T18:40:21.285Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-35410 (GCVE-0-2022-35410)

    Vulnerability from cvelistv5 – Published: 2022-07-08 17:35 – Updated: 2024-08-03 09:36
    VLAI
    Summary
    mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T09:36:44.366Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://0xacab.org/jvoisin/mat2/-/issues/174"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://0xacab.org/jvoisin/mat2/-/commit/beebca4bf1cd3b935824c966ce077e7bcf610385"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://dustri.org/b/mat2-0130.html"
              },
              {
                "name": "DSA-5185",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "https://www.debian.org/security/2022/dsa-5185"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-07-16T02:06:06.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://0xacab.org/jvoisin/mat2/-/issues/174"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://0xacab.org/jvoisin/mat2/-/commit/beebca4bf1cd3b935824c966ce077e7bcf610385"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://dustri.org/b/mat2-0130.html"
            },
            {
              "name": "DSA-5185",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "https://www.debian.org/security/2022/dsa-5185"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2022-35410",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://0xacab.org/jvoisin/mat2/-/issues/174",
                  "refsource": "MISC",
                  "url": "https://0xacab.org/jvoisin/mat2/-/issues/174"
                },
                {
                  "name": "https://0xacab.org/jvoisin/mat2/-/commit/beebca4bf1cd3b935824c966ce077e7bcf610385",
                  "refsource": "MISC",
                  "url": "https://0xacab.org/jvoisin/mat2/-/commit/beebca4bf1cd3b935824c966ce077e7bcf610385"
                },
                {
                  "name": "https://dustri.org/b/mat2-0130.html",
                  "refsource": "MISC",
                  "url": "https://dustri.org/b/mat2-0130.html"
                },
                {
                  "name": "DSA-5185",
                  "refsource": "DEBIAN",
                  "url": "https://www.debian.org/security/2022/dsa-5185"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2022-35410",
        "datePublished": "2022-07-08T17:35:23.000Z",
        "dateReserved": "2022-07-08T00:00:00.000Z",
        "dateUpdated": "2024-08-03T09:36:44.366Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }