First published: Thu Sep 26 2024(Updated: )
The goTenna Pro ATAK Plugin's default settings are to share Automatic Position, Location, and Information (PLI) updates every 60 seconds once the plugin is active and goTenna is connected. Users that are unaware of their settings and have not activated encryption before a mission may accidentally broadcast their location unencrypted. It is advised to verify PLI settings are the desired rate and activate encryption prior to mission. Update to the latest Plugin to disable this default setting.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
goTenna | <2.0.7 |
goTenna recommends that users mitigate these vulnerabilities by performing the following updates: * ATAK Plugin: v2.0.7 or greater
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43814 has been rated as a medium severity vulnerability due to the risk of unintended data sharing without encryption.
To mitigate CVE-2024-43814, users should ensure that encryption settings are activated before starting a mission.
CVE-2024-43814 affects the goTenna Pro ATAK Plugin versions up to 2.0.7.
The primary risk associated with CVE-2024-43814 is the potential exposure of sensitive location and operational information due to default sharing settings.
CVE-2024-43814 shares Automatic Position, Location, and Information updates every 60 seconds by default when active.