Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-45723


The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF. This only applies to the optional broadcast of an encryption key, so it is advised to share the key with local QR code for higher security operations.


Published

2024-09-26T18:15:07.927

Last Modified

2024-10-17T17:15:12.110

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-338

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gotenna gotenna < 2.0.7 Yes

References