CVE-2024-41722 - CVE House
Back to Database
Status published Medium CVE-2024-41722

goTenna Pro ATAK Plugin Weak Authentication

Vulnerability Description

In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the device is being used in an unencrypted environment or if the cryptography has already been compromised. It is advised to use encryption shared with local QR code for higher security operations.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-41722

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Erwin Karincic, Clayton Smith, and Dale Wooden reported this these vulnerabilities to CISA.

Affected Vendor

Affected Software

Pro ATAK Plugin
Vulnerable Versions:
0

Timeline

Official Publish: September 26th, 2024
Last Modified: October 17th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.