CVE-2024-43108

MEDIUM

goTenna Pro ATAK Plugin - Info Disclosure

Title source: llm
STIX 2.1

Description

The goTenna Pro ATAK Plugin uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message. It is advised to continue to use encryption in the plugin and update to the current release for enhanced encryption protocols.

Scores

CVSS v3 5.3
EPSS 0.0004
EPSS Percentile 13.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-353 CWE-345
Status published
Products (1)
gotenna/gotenna < 2.0.7
Published Sep 26, 2024
Tracked Since Feb 18, 2026