PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-43694 goTenna CVE debrief

CVE-2024-43694 is a medium-severity vulnerability in the goTenna Pro ATAK Plugin affecting versions 1.9.12 and earlier. The issue involves encryption keys being stored alongside a static initialization vector (IV) on End User Devices (EUDs), enabling complete key decryption if the device is physically compromised. This cryptographic weakness allows an attacker with physical access to decrypt all encrypted broadcast communications using keys extracted from the device. The vulnerability was disclosed by CISA on September 26, 2024, with an update published October 17, 2024. goTenna has released ATAK Plugin version 2.0.7 or greater to address this issue. The attack requires physical access to and control of the EUD, limiting exploitability but maintaining significant impact for targeted scenarios involving device seizure or loss.

Vendor
goTenna
Product
Pro ATAK Plugin
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2024-09-26
Original CVE updated
2024-10-17
Advisory published
2024-09-26
Advisory updated
2024-10-17

Who should care

Organizations deploying goTenna Pro ATAK Plugin in tactical, emergency response, or field operations where device physical security may be challenged; security teams responsible for mobile device management and encrypted communications infrastructure; and operators requiring assured confidentiality of broadcast communications in contested environments.

Technical summary

The goTenna Pro ATAK Plugin (versions ≤1.9.12) stores encryption keys with a static initialization vector on the End User Device. This cryptographic implementation flaw enables an attacker with physical device access to extract and decrypt all stored keys, subsequently allowing decryption of all encrypted broadcast communications. The vulnerability requires local physical access (AV:P) with low attack complexity. Remediation involves updating to ATAK Plugin v2.0.7+ and implementing defense-in-depth measures including device-level encryption, access controls, key rotation, and operational security practices for key distribution.

Defensive priority

medium

Recommended defensive actions

  • Update goTenna Pro ATAK Plugin to version 2.0.7 or greater as specified in vendor remediations.
  • Implement strong physical access controls and device encryption on all End User Devices (EUDs) to mitigate physical compromise risk.
  • Use discreet callsigns and key names that do not disclose location, team size, or team composition.
  • Establish regular encryption key rotation following industry best practices.
  • For Pro deployments, utilize QR code-based key exchange and transmit keys at reduced power (0.5 Watts) in secured areas only.
  • Implement layered encryption for communications with individuals and teams.
  • Contact [email protected] for additional assistance with secure operating procedures.

Evidence notes

Vulnerability description and remediation guidance sourced from CISA ICS Advisory ICSA-24-270-05 (Update A). CVSS 3.1 vector AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N confirms physical attack vector with high confidentiality impact. Affected product version confirmed as <=1.9.12; fixed version 2.0.7 or greater specified in vendor remediations.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-43694 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-43694

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-43694 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-43694

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-270-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-05

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.