Weak password requirements in ATAK Plugin - CVE-2024-45374

 

Weak password requirements in ATAK Plugin - CVE-2024-45374

Published: October 1, 2024


Vulnerability identifier: #VU97905
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-45374
CWE-ID: CWE-521
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to weak password requirements for the QR broadcast message. A remote attacker on the local network can decrypt it and use it to decrypt all future and past messages sent via encrypted broadcast.


Affected software

ATAK Plugin

How to mitigate CVE-2024-45374

Install updates from vendor's website.

ATAK Plugin - update to 2.0.7

External References

Related Security Bulletins