← back
CVE-2024-45838

goTenna Pro ATAK Plugin Cleartext Transmission of Sensitive Information

CVSS 2.3 LOWEPSS 0.1%CWE-319
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 2.3EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
26 Sep 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It is advised to not use sensitive information in callsigns when using this and previous versions of the plugin. Update to current plugin version which uses AES-256 encryption for callsigns in encrypted operation
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →