CVE-2024-43814 - CVE House
Back to Database
Status published Medium CVE-2024-43814

goTenna Pro ATAK Plugin Insertion of Sensitive Information Into Sent Data

Vulnerability Description

The goTenna Pro ATAK Plugin's default settings are to share Automatic Position, Location, and Information (PLI) updates every 60 seconds once the plugin is active and goTenna is connected. Users that are unaware of their settings and have not activated encryption before a mission may accidentally broadcast their location unencrypted. It is advised to verify PLI settings are the desired rate and activate encryption prior to mission. Update to the latest Plugin to disable this default setting.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-43814

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Erwin Karincic, Clayton Smith, and Dale Wooden reported this these vulnerabilities to CISA.

Affected Vendor

Affected Software

Pro ATAK Plugin
Vulnerable Versions:
0

Timeline

Official Publish: September 26th, 2024
Last Modified: October 17th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)