The goTenna Pro ATAK Plugin encryption key name is always sent unencrypted when the key is sent over RF through a broadcast message. It is advised to share the encryption key via local QR for higher security operations.
History

Thu, 17 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
Description The goTenna Pro ATAK Plugin broadcast key name is always sent unencrypted and could reveal the location of operation. The goTenna Pro ATAK Plugin encryption key name is always sent unencrypted when the key is sent over RF through a broadcast message. It is advised to share the encryption key via local QR for higher security operations.

Mon, 07 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Gotenna
Gotenna gotenna
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:gotenna:gotenna:*:*:*:*:*:atak:*:*
Vendors & Products Gotenna
Gotenna gotenna

Thu, 26 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Sep 2024 18:00:00 +0000

Type Values Removed Values Added
Description The goTenna Pro ATAK Plugin broadcast key name is always sent unencrypted and could reveal the location of operation.
Title goTenna Pro ATAK Plugin Insertion of Sensitive Information Into Sent Data
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-09-26T17:42:16.640Z

Updated: 2024-10-17T17:01:08.613Z

Reserved: 2024-09-24T14:22:20.139Z

Link: CVE-2024-41931

cve-icon Vulnrichment

Updated: 2024-09-26T18:30:54.466Z

cve-icon NVD

Status : Modified

Published: 2024-09-26T18:15:06.453

Modified: 2024-10-17T17:15:11.773

Link: CVE-2024-41931

cve-icon Redhat

No data.