The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and use it to decrypt all future and past messages sent via encrypted broadcast with that particular key. This only applies when the key is broadcasted over RF. This is an optional feature, so it is advised to use local QR encryption key sharing for additional security on this and previous versions.
History

Thu, 17 Oct 2024 16:30:00 +0000

Type Values Removed Values Added
Description In the goTenna Pro ATAK Plugin application, the encryption keys are stored along with a static IV on the device. This allows for complete decryption of keys stored on the device. This allows an attacker to decrypt all encrypted broadcast communications based on broadcast keys stored on the device. The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and use it to decrypt all future and past messages sent via encrypted broadcast with that particular key. This only applies when the key is broadcasted over RF. This is an optional feature, so it is advised to use local QR encryption key sharing for additional security on this and previous versions.

Mon, 07 Oct 2024 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Gotenna
Gotenna gotenna
Weaknesses CWE-922
CPEs cpe:2.3:a:gotenna:gotenna:*:*:*:*:*:atak:*:*
Vendors & Products Gotenna
Gotenna gotenna

Thu, 26 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
Description In the goTenna Pro ATAK Plugin application, the encryption keys are stored along with a static IV on the device. This allows for complete decryption of keys stored on the device. This allows an attacker to decrypt all encrypted broadcast communications based on broadcast keys stored on the device.
Title goTenna Pro ATAK Plugin Weak Password Requirements
Weaknesses CWE-521
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-09-26T17:08:13.256Z

Updated: 2024-10-17T16:15:16.527Z

Reserved: 2024-09-24T14:22:20.065Z

Link: CVE-2024-45374

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2024-09-26T18:15:07.687

Modified: 2024-10-17T17:15:11.997

Link: CVE-2024-45374

cve-icon Redhat

No data.