Skip to main content
Home

Main navigation

  • REC Home
  • Apply
    • REC Services Rate Card & Policies
    • LPFM Construction Completed
    • LPFM License Modification
    • New FM Booster Station
    • New Class D FM Station in Alaska
    • New Low Power FM (LPFM) Station
  • Initiatives
    • RM-11846: Rural NCE Stations
    • RM-11909: LP-250 / Simple 250
    • WIDE-FM
    • RM-11952: Translator Reform
    • RM-11843: 8 Meter Ham Band
    • PACE - LPFM Compliance
  • Services
  • Tools
    • Today's FCC Activity
    • Broadcast Data Query
    • Field strength curves
    • Runway slope
    • Tower finder
    • FM MODEL-RF Exposure Study
    • More tools
    • Developers - API
  • LPFM
    • Learn about LPFM
      • Basics of LPFM
      • Self Inspection Checklist
      • Underwriting Compliance Guide
      • Frequently Asked Questions
      • FCC Rules for LPFM
      • HD Radio for LPFM
      • Transmitters certified for LPFM
      • Interference from FM translators
      • RadioDNS for LPFM Stations
    • 2023 Window REC Client Portal
    • myLPFM - LPFM Station Management
    • LPFM Station Directory
    • Spare call signs
    • REC PACE Program
    • More about LPFM
  • Reference
    • Pending FCC Applications
    • FCC Filing Fees
    • Radio License Renewal Deadlines
    • FCC Record/FCC Reports
    • Pirate Radio Enforcement Data
    • Premises Info System (PREMIS)
    • ITU and other international documents
    • Recent FCC Callsign Activity
    • FCC Enforcement Actions
    • Federal Register
    • Recent CAP/Weather Alerts
    • Legal Unlicensed Broadcasting
    • More reference tools
  • LPFM Window
  • About
    • REC in the Media
    • Supporting REC's Efforts
    • Recommendations
    • FCC Filings and Presentations
    • Our Jingles
    • REC Radio History Project
    • Delmarva FM / Riverton Radio Project
    • J1 Radio / Japanese Broadcasting
    • Japan Earthquake Data
    • REC Systems Status
    • eLMS: Enhanced LMS Data Project
    • Open Data at REC
    • Our Objectives
  • Contact

Breadcrumb

  • Home

Operational Status

Michi on YouTube

Most popular

fcc.today - real time updates on application activity from the FCC Media Bureau.  fccdata.org - the internet's most comprehensive FCC database lookup tool.  myLPFM.com - Low Power FM channel search and station management tool.  REC Broadcast Services - professional LPFM and FM translator filing services. 

Other tools & info

  • Filing Window Tracking
  • Enforcement Actions
  • REC Advisory Letters
  • FAQ-Knowledge Base
  • U/D Ratio Calculator
  • Propagation Curves
  • Runway Slope/REC TOWAIR
  • Coordinate Conversion
  • PREMIS: Address Profile
  • Spare Call Sign List
  • FCC (commercial) filing fees
  • Class D FM stations in Alaska
  • ARRR: Pirate radio notices
  • Unlicensed broadcasting (part 15)
  • FMmap - broadcast atlas
  • Federal Register
  • Rate Card & Policies
  • REC system status
  • Server Status
  • Complete site index
Cirrus Streaming - Radio Streaming Services - Podcasting & On-demand - Mobile Apps - Advertising

REC LPFM Advisory Letter #15 - EAS Vulnerability, especially in DASDEC versions other than 4.x and 5.x

By Michi Bradley | 1:00 PM EDT, Sun March 10, 2024

The following information is from the Society of Broadcast Engineers (SBE).  REC's additional comments are in bold.

On Aug. 1, 2022, The Federal Emergency Management Agency (FEMA) released an IPAWS advisory noting a vulnerability in the Emergency Alert System (EAS). EAS encoder/decoders that have not been updated to the most recent software versions, could allow unauthorized access to issue EAS alerts. 

The vulnerability is public knowledge and will be demonstrated to a large public audience in the coming weeks at a trade convention.

FEMA strongly encourages EAS participants to ensure that:
1. EAS devices and supporting systems are up to date with the most recent software versions and security patches;
2. EAS devices are protected by a firewall;
3. EAS devices and supporting systems are monitored and audit logs are regularly reviewed looking for unauthorized access.

CNN reports that the issue is specific to Monroe DASDEC units. The Indiana Association of Broadcasters (IAB) has confirmed this with FEMA and the NAB.

The IAB notes that this vulnerability is not new. It was first reported in 2013 during the so-called zombie attacks, however, it appears that the security patch provided by Monroe at the time did not completely resolve the problem. Several software updates have been issued since then, and stations that have updated to version 4.0 or higher are secure. However, any device that has not been updated to version 4.0 or 5.X remains vulnerable. The cybersecurity researcher referenced in the CNN article was apparently able to identify a number of EAS devices that could be hacked. He is apparently planning to share his finding at a public conference on Aug. 11-14.

REC is aware that some LPFM stations may be operating a DASDEC EAS with version 3.x.  It is very important that you consider making the upgrade to version 4.x.  This is not a sales pitch.  This is a serious issue.  We are not aware if Monroe will be making an emergency patch for 3.x users, so the most prudent thing for LPFM stations that are on DASDEC II version 3.x or earlier is to upgrade to version 4.x if their equipment is compatible (DASDECs of earlier than 2014 vintage may have a hardware incompatibility).   

For more information on the software upgrade for DASDEC units only, visit:
https://www.digitalalertsystems.com/EAS_DAS/V4_software.html

Regardless of which EAS your station has, you should take the time to determine your current software version and contact your EAS manufacturer to determine if you have the most current version of  your software.   Also, please follow the recommendations above to assure that your EAS is safe from cyberattacks.

EAS manufacturer websites:
https://www.digitalalertsystems.com/
http://www.gorman-redlich.com/
https://www.sagealertingsystems.com/

Receiving REC Advisory Letters by RSS

If you are using newsreader software or certain e-mail clients such as Mozilla Thunderbird, you can set it up to receive these bulletins as an RSS news feed.  The feed URL is: https://recnet.com/taxonomy/term/76/feed

Original version: August 5, 2022
Updated March 10, 2024 to reflect version 5.x from DASDEC.  All stations should be on a 5.X version in order to comply with the new CAP Polling requirements.

REC Essentials

  • FCC.TODAY
  • FCCdata.org
  • myLPFM Station Management
  • REC site map

The More You Know...

  • Unlicensed Broadcasting
  • Class D Stations for Alaska
  • Broadcasting in Japan
  • Our Jingles

Other REC sites

  • J1 Radio
  • REC Delmarva FM
  • Japan Earthquake Information
  • API for developers

But wait, there's more!

  • Join NFCB
  • Pacifica Network
  • LPFM Wiki
  • Report a bug with an REC system

Copyright © REC Networks - All Rights Reserved
EU cookie policy

Please show your support by using the Ko-Fi link at the bottom of the page. Thank you for supporting REC's efforts!