CVE-2024-45723
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Sep 26, 2024
Updated: Oct 17, 2024
CWE ID 338
Summary
CVE-2024-45723: The goTenna Pro ATAK Plugin is vulnerable to password guessing attacks due to its use of an insecure random number generation method for generating passwords when sharing cryptographic keys over RF. Attackers can potentially capture and decode broadcasted encryption keys, making it easier for them to brute force the password associated with a specific device. However, it's recommended to share keys using local QR codes instead to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share