Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r9gf-v8wf-j3wq

Опубликовано: 26 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

The goTenna Pro ATAK Plugin has a payload length vulnerability that makes it possible to tell the length of the payload regardless of the encryption used.

The goTenna Pro ATAK Plugin has a payload length vulnerability that makes it possible to tell the length of the payload regardless of the encryption used.

EPSS

Процентиль: 13%
0.00042
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-203
CWE-204

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payload regardless of the encryption used.

EPSS

Процентиль: 13%
0.00042
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-203
CWE-204