The goTenna Pro ATAK Plugin does not use SecureRandom when generating
passwords for sharing cryptographic keys. The random function in use
makes it easier for attackers to brute force this password if the
broadcasted encryption key is captured over RF. This only applies to the
optional broadcast of an encryption key, so it is advised to share the
key with local QR code for higher security operations.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The goTenna Pro ATAK Plugin does not use SecureRandom when generating its cryptographic keys. The random function in use is not suitable for cryptographic use. | The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF. This only applies to the optional broadcast of an encryption key, so it is advised to share the key with local QR code for higher security operations. |
Mon, 07 Oct 2024 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gotenna gotenna
|
|
CPEs | cpe:2.3:a:gotenna:gotenna:*:*:*:*:*:atak:*:* | |
Vendors & Products |
Gotenna gotenna
|
Thu, 26 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gotenna
Gotenna pro Atak Plugin |
|
CPEs | cpe:2.3:a:gotenna:pro_atak_plugin:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gotenna
Gotenna pro Atak Plugin |
|
Metrics |
ssvc
|
Thu, 26 Sep 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The goTenna Pro ATAK Plugin does not use SecureRandom when generating its cryptographic keys. The random function in use is not suitable for cryptographic use. | |
Title | goTenna Pro ATAK Plugin Use of Cryptographically Weak Pseudo-Random Number Generator | |
Weaknesses | CWE-338 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2024-09-26T17:37:26.917Z
Updated: 2024-10-17T16:56:55.574Z
Reserved: 2024-09-24T14:22:20.122Z
Link: CVE-2024-45723
Vulnrichment
Updated: 2024-09-26T17:59:45.595Z
NVD
Status : Modified
Published: 2024-09-26T18:15:07.927
Modified: 2024-10-17T17:15:12.110
Link: CVE-2024-45723
Redhat
No data.