Loading HuntDB...

gotenna

3 Products 19 CVEs

CVE Severity Distribution (All Time)

Critical
0
High
0
Medium
9
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 19 CVEs

Recent CVEs

View all
CVE-2024-43814 MEDIUM 9 months, 1 week ago

The goTenna Pro ATAK Plugin's default settings are to share Automatic Position, Location, and Information (PLI) updates every 60 seconds once the p…

CVE-2024-41715 MEDIUM 9 months, 1 week ago

The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to…

CVE-2024-41931 MEDIUM 9 months, 1 week ago

The goTenna Pro ATAK Plugin encryption key name is always sent unencrypted when the key is sent over RF through a broadcast message. It is advised …

CVE-2024-41722 MEDIUM 9 months, 1 week ago

In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a softw…

CVE-2024-45723 MEDIUM 9 months, 1 week ago

The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it…

CVE-2024-45838 MEDIUM 9 months, 1 week ago

The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It is advised to not use sensitive information in callsigns when using this and…

CVE-2024-47130 UNKNOWN 9 months, 1 week ago

The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group messages. It is advised to upd…

CVE-2024-47129 UNKNOWN 9 months, 1 week ago

The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell th…

CVE-2024-47128 UNKNOWN 9 months, 1 week ago

The goTenna Pro App encryption key name is always sent unencrypted when the key is shared over RF through a broadcast message. It is advised to sha…

CVE-2024-43108 MEDIUM 9 months, 1 week ago

The goTenna Pro ATAK Plugin uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This l…