Vulnerabilities > CVE-2024-43694 - Insecure Storage of Sensitive Information vulnerability in Gotenna Atak Plugin

047910
CVSS 6.5 - MEDIUM
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
low complexity
gotenna
CWE-922

Summary

In the goTenna Pro ATAK Plugin application, the encryption keys are stored along with a static IV on the device. This allows for complete decryption of keys stored on the device. This allows an attacker to decrypt all encrypted broadcast communications based on broadcast keys stored on the device.

Vulnerable Configurations

Part Description Count
Application
Gotenna
1

Common Weakness Enumeration (CWE)