#VU97905 Weak password requirements in ATAK Plugin - CVE-2024-45374

 

#VU97905 Weak password requirements in ATAK Plugin - CVE-2024-45374

Published: October 1, 2024


Vulnerability identifier: #VU97905
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-45374
CWE-ID: CWE-521
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
ATAK Plugin
Software vendor:
goTenna

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to weak password requirements for the QR broadcast message. A remote attacker on the local network can decrypt it and use it to decrypt all future and past messages sent via encrypted broadcast.


Remediation

Install updates from vendor's website.

External links