SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-45723

The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF.

HIGH 7.1EPSS 0.14%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.14%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF. This only applies to the optional broadcast of an encryption key, so it is advised to share the key with local QR code for higher security operations.

CVSS 4.0
7.1 HIGHCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.14% probability · 4th percentile
CISA KEV
Not listed
Weakness
CWE-338
Affected
gotenna/gotenna
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.