Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vcw2-g6r2-h5hh

Опубликовано: 26 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

goTenna Pro ATAK Plugin by default enables frequent unencrypted Position, Location and Information (PLI) transmission. This transmission is done without user's knowledge, revealing the exact location transmitted in unencrypted form.

goTenna Pro ATAK Plugin by default enables frequent unencrypted Position, Location and Information (PLI) transmission. This transmission is done without user's knowledge, revealing the exact location transmitted in unencrypted form.

EPSS

Процентиль: 17%
0.00053
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-201

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

The goTenna Pro ATAK Plugin's default settings are to share Automatic Position, Location, and Information (PLI) updates every 60 seconds once the plugin is active and goTenna is connected. Users that are unaware of their settings and have not activated encryption before a mission may accidentally broadcast their location unencrypted. It is advised to verify PLI settings are the desired rate and activate encryption prior to mission. Update to the latest Plugin to disable this default setting.

EPSS

Процентиль: 17%
0.00053
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-201