CVE-2024-45838

MEDIUM

goTenna Pro ATAK Plugin < 2.0.7 - Cleartext Transmission of Sensitive Information

Title source: llm
STIX 2.1

Description

The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It is advised to not use sensitive information in callsigns when using this and previous versions of the plugin. Update to current plugin version which uses AES-256 encryption for callsigns in encrypted operation

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource government-resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-05

Scores

CVSS v3 4.3
EPSS 0.0009
EPSS Percentile 0.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-319
Status published
Products (1)
gotenna/gotenna < 2.0.7
Published Sep 26, 2024
Tracked Since Feb 18, 2026