Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xw45-w4r2-g9c2

Опубликовано: 26 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 6
CVSS3: 6.5

Описание

In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing gotenna mesh networks. This vulnerability can be exploited if the device is being used in a unencrypted environment or if the cryptography has already been compromised.

In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing gotenna mesh networks. This vulnerability can be exploited if the device is being used in a unencrypted environment or if the cryptography has already been compromised.

EPSS

Процентиль: 6%
0.00029
Низкий

6 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-1390

Связанные уязвимости

CVSS3: 6.5
nvd
11 месяцев назад

In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the device is being used in an unencrypted environment or if the cryptography has already been compromised. It is advised to use encryption shared with local QR code for higher security operations.

EPSS

Процентиль: 6%
0.00029
Низкий

6 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-1390