Vulnerability Description
The goTenna Pro ATAK Plugin uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message. It is advised to continue to use encryption in the plugin and update to the current release for enhanced encryption protocols.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gotenna | Gotenna | < 2.0.7 |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-05Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2024-43108?
CVE-2024-43108 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The goTenna Pro ATAK Plugin uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can ac...
How severe is CVE-2024-43108?
CVE-2024-43108 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-43108?
Check the references section above for vendor advisories and patch information. Affected products include: Gotenna Gotenna.