CVE-2024-43694

In the goTenna Pro ATAK Plugin application, the encryption keys are stored along with a static IV on the device. This allows for complete decryption of keys stored on the device. This allows an attacker to decrypt all encrypted broadcast communications based on broadcast keys stored on the device.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-05 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:gotenna:atak_plugin:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-26 18:15

Updated : 2024-10-07 19:40


NVD link : CVE-2024-43694

Mitre link : CVE-2024-43694

CVE.ORG link : CVE-2024-43694


JSON object : View

Products Affected

gotenna

  • atak_plugin
CWE
CWE-922

Insecure Storage of Sensitive Information