CVE-2024-43694

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Oct 7, 2024
CWE ID 922

Summary

CVE-2024-43694 is a vulnerability affecting the goTenna Pro ATAK Plugin application. It permits unauthorized access by storing encryption keys alongside a static IV on the device. An attacker can exploit this flaw to decrypt all encrypted broadcast communications based on the keys stored on the device, putting sensitive information at risk. This vulnerability poses a significant threat to secure communications using the goTenna Pro ATAK Plugin.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share