CVE Published: 26/09/2024 |
CVE Updated: 17/10/2024 |
CVE Year: 2024 Source: icscert |
Vendor: goTenna |
Product: Pro ATAK Plugin Status : PUBLISHED
CVE-2024-41722 Description
In the goTenna Pro ATAK Plugin there is a vulnerability that makes it
possible to inject any custom message with any GID and Callsign using a
software defined radio in existing goTenna mesh networks. This
vulnerability can be exploited if the device is being used in an
unencrypted environment or if the cryptography has already been
compromised. It is advised to use encryption shared with local QR code
for higher security operations.
Metrics
CVSS Version: 3.1 |
Base Score: 6.5 MEDIUM Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N