CVE-2024-22186
The application suffers from a privilege escalation vulnerability. An attacker logged in as guest can escalate his privileges by poisoning the cookie to become administrator.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.55%
- CWE
- CWE-565
- Published
- 2024-04-18
- Last modified
- 2026-03-13
Affected products
- Electrolink Compact DAB Transmitter
- Electrolink Compact DAB Transmitter
- Electrolink Compact DAB Transmitter
- Electrolink Medium DAB Transmitter
- Electrolink Medium DAB Transmitter
- Electrolink Medium DAB Transmitter
- Electrolink High Power DAB Transmitter
- Electrolink High Power DAB Transmitter
Weakness type
Related vulnerabilities
- CVE-2026-85181 — CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum
- CVE-2026-75757 — AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a sibling subdomain
- CVE-2026-53871 — Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged hermes_profile Cookie
- CVE-2026-8337 — Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveys
- CVE-2026-0257 — PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
- CVE-2026-39963 — Serendipity: Host Header Injection enables authentication cookie scoping to an attacker-controlled domain
- CVE-2026-39324 — Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization
- CVE-2026-5130 — Debugger & Troubleshooter <= 1.3.2 - Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation