PatchSiren cyber security CVE debrief
CVE-2024-45723 goTenna CVE debrief
The goTenna Pro ATAK Plugin uses an insecure random number generator when creating passwords for cryptographic key sharing, enabling brute-force attacks against broadcasted encryption keys captured over RF. This vulnerability affects versions 1.9.12 and earlier. The issue was disclosed by CISA on September 26, 2024, with an advisory update on October 17, 2024.
- Vendor
- goTenna
- Product
- Pro ATAK Plugin
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-09-26
- Original CVE updated
- 2024-10-17
- Advisory published
- 2024-09-26
- Advisory updated
- 2024-10-17
Who should care
Organizations using goTenna Pro ATAK Plugin for tactical communications, particularly military, law enforcement, emergency response, and critical infrastructure teams who rely on encrypted RF communications for operational security.
Technical summary
The goTenna Pro ATAK Plugin fails to use java.security.SecureRandom when generating passwords for cryptographic key sharing operations. Instead, it employs a less secure random function that reduces password entropy, enabling attackers to brute-force passwords if they capture the broadcasted encryption key over RF. This vulnerability specifically affects the optional RF broadcast feature for encryption key distribution. The affected product is goTenna Pro ATAK Plugin version 1.9.12 and earlier. CVSS 3.1 score: 6.5 (Medium).
Defensive priority
medium
Recommended defensive actions
- Update to ATAK Plugin version 2.0.7 or greater
- Use QR codes for local encryption key sharing instead of RF broadcast
- Implement discreet callsigns and key names that do not disclose location or team information
- Secure end-user devices with encryption and regular software updates
- Follow encryption key rotation best practices
- When broadcasting is necessary, operate in secured areas at reduced power (0.5 Watts)
- Implement layered encryption for communications management
- Contact [email protected] for questions regarding secure operating practices
Evidence notes
CISA ICS Advisory ICSA-24-270-05 (Update A) documents that the plugin fails to use SecureRandom for password generation, making brute-force attacks feasible against RF-captured encryption keys. The advisory was initially published September 26, 2024, and updated October 17, 2024.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-45723 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-45723
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-45723 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-45723
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-270-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.