Weak password requirements in ATAK Plugin - CVE-2024-45374
Published: October 1, 2024
Vulnerability identifier: #VU97905
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-45374
CWE-ID: CWE-521
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to weak password requirements for the QR broadcast message. A remote attacker on the local network can decrypt it and use it to decrypt all future and past messages sent via encrypted broadcast.
Affected software
ATAK Plugin
How to mitigate CVE-2024-45374
Install updates from vendor's website.
ATAK Plugin - update to 2.0.7