The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It
is advised to not use sensitive information in callsigns when using this
and previous versions of the plugin. Update to current plugin version
which uses AES-256 encryption for callsigns in encrypted operation
Metrics
Affected Vendors & Products
References
History
Thu, 17 Oct 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The goTenna Pro ATAK Plugin does not encrypt the callsigns of its users. These callsigns reveal information about the users and can also be leveraged for other vulnerabilities. | The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It is advised to not use sensitive information in callsigns when using this and previous versions of the plugin. Update to current plugin version which uses AES-256 encryption for callsigns in encrypted operation |
Mon, 07 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gotenna gotenna
|
|
CPEs | cpe:2.3:a:gotenna:gotenna:*:*:*:*:*:atak:*:* | |
Vendors & Products |
Gotenna gotenna
|
Thu, 26 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gotenna
Gotenna pro Atak Plugin |
|
CPEs | cpe:2.3:a:gotenna:pro_atak_plugin:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gotenna
Gotenna pro Atak Plugin |
|
Metrics |
ssvc
|
Thu, 26 Sep 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The goTenna Pro ATAK Plugin does not encrypt the callsigns of its users. These callsigns reveal information about the users and can also be leveraged for other vulnerabilities. | |
Title | goTenna Pro ATAK Plugin Cleartext Transmission of Sensitive Information | |
Weaknesses | CWE-319 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2024-09-26T17:31:45.575Z
Updated: 2024-10-17T16:54:51.865Z
Reserved: 2024-09-24T14:22:20.114Z
Link: CVE-2024-45838
Vulnrichment
Updated: 2024-09-26T18:05:51.099Z
NVD
Status : Modified
Published: 2024-09-26T18:15:08.170
Modified: 2024-10-17T17:15:12.220
Link: CVE-2024-45838
Redhat
No data.