Insecure Storage of Sensitive Information in ATAK Plugin - CVE-2024-43694

 

Insecure Storage of Sensitive Information in ATAK Plugin - CVE-2024-43694

Published: October 1, 2024


Vulnerability identifier: #VU97906
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-43694
CWE-ID: CWE-922
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to the encryption keys are stored along with a static IV on the device. An authenticated attacker with physical access can decrypt all encrypted broadcast communications based on broadcast keys stored on the device.


Affected software

ATAK Plugin

How to mitigate CVE-2024-43694

Install updates from vendor's website.

ATAK Plugin - update to 2.0.7

External References

Related Security Bulletins