CVE-2024-43694
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Sep 26, 2024
Updated: Oct 7, 2024
CWE ID 922
Summary
CVE-2024-43694 is a vulnerability affecting the goTenna Pro ATAK Plugin application. It permits unauthorized access by storing encryption keys alongside a static IV on the device. An attacker can exploit this flaw to decrypt all encrypted broadcast communications based on the keys stored on the device, putting sensitive information at risk. This vulnerability poses a significant threat to secure communications using the goTenna Pro ATAK Plugin.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- goTenna