CVE-2024-45374

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Oct 17, 2024
CWE ID 521
CWE ID 922

Summary

CVE-2024-45374 is a vulnerability affecting the goTenna Pro ATAK plugin. The issue lies in the use of a weak password for encrypting keys shared via the key broadcast method. If an attacker captures the broadcasted encryption key and successfully cracks the password through brute force attacks, they can decrypt all past and future messages encrypted with that key. This vulnerability only applies when the key is shared over RF, and it is recommended to use QR code encryption key sharing for enhanced security on this and previous plugin versions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share