The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF. This only applies to the optional broadcast of an encryption key, so it is advised to share the key with local QR code for higher security operations.
History

Thu, 17 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
Description The goTenna Pro ATAK Plugin does not use SecureRandom when generating its cryptographic keys. The random function in use is not suitable for cryptographic use. The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF. This only applies to the optional broadcast of an encryption key, so it is advised to share the key with local QR code for higher security operations.

Mon, 07 Oct 2024 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Gotenna gotenna
CPEs cpe:2.3:a:gotenna:gotenna:*:*:*:*:*:atak:*:*
Vendors & Products Gotenna gotenna

Thu, 26 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Gotenna
Gotenna pro Atak Plugin
CPEs cpe:2.3:a:gotenna:pro_atak_plugin:*:*:*:*:*:*:*:*
Vendors & Products Gotenna
Gotenna pro Atak Plugin
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Sep 2024 17:45:00 +0000

Type Values Removed Values Added
Description The goTenna Pro ATAK Plugin does not use SecureRandom when generating its cryptographic keys. The random function in use is not suitable for cryptographic use.
Title goTenna Pro ATAK Plugin Use of Cryptographically Weak Pseudo-Random Number Generator
Weaknesses CWE-338
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-09-26T17:37:26.917Z

Updated: 2024-10-17T16:56:55.574Z

Reserved: 2024-09-24T14:22:20.122Z

Link: CVE-2024-45723

cve-icon Vulnrichment

Updated: 2024-09-26T17:59:45.595Z

cve-icon NVD

Status : Modified

Published: 2024-09-26T18:15:07.927

Modified: 2024-10-17T17:15:12.110

Link: CVE-2024-45723

cve-icon Redhat

No data.