Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-45838


The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It is advised to not use sensitive information in callsigns when using this and previous versions of the plugin. Update to current plugin version which uses AES-256 encryption for callsigns in encrypted operation


Published

2024-09-26T18:15:08.170

Last Modified

2024-10-17T17:15:12.220

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-319

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gotenna gotenna < 2.0.7 Yes

References