PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-45838 goTenna CVE debrief

The goTenna Pro ATAK Plugin (versions 1.9.12 and earlier) transmits callsigns in plaintext within encrypted messages, exposing potentially sensitive identifier information to network observers despite the message payload being encrypted. This represents a confidentiality gap where operational security assumptions about encrypted communications do not extend to participant identification metadata. The vendor has addressed this in version 2.0.7 through implementation of AES-256 encryption for callsigns during encrypted operations.

Vendor
goTenna
Product
Pro ATAK Plugin
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2024-09-26
Original CVE updated
2024-10-17
Advisory published
2024-09-26
Advisory updated
2024-10-17

Who should care

Organizations using goTenna Pro ATAK Plugin for tactical communications, particularly military, emergency response, and critical infrastructure operators where participant anonymity or operational security is required. System administrators managing ATAK deployments and information security officers responsible for communications security in field operations.

Technical summary

The goTenna Pro ATAK Plugin fails to encrypt callsign metadata within otherwise encrypted messages, allowing network observers to identify communication participants even when message content remains confidential. This vulnerability affects plugin versions through 1.9.12. The vendor's remediation in version 2.0.7 implements AES-256 encryption for callsigns during encrypted operations. Interim mitigations include operational security practices for callsign selection and key management procedures.

Defensive priority

medium

Recommended defensive actions

  • Update goTenna Pro ATAK Plugin to version 2.0.7 or greater to obtain AES-256 encryption for callsigns in encrypted operation
  • Select callsigns and key names that do not disclose sensitive operational information such as location, team size, or team name
  • Implement strong security measures on all end-user devices including encryption and regular software updates
  • Rotate encryption keys regularly according to industry best practices
  • For Pro deployments, utilize QR codes for secure exchange of encryption keys
  • When broadcasting encryption keys, ensure transmission occurs in secured areas at reduced power (0.5 Watts)
  • Implement layered encryption keys to manage communications securely across individuals and teams
  • Contact [email protected] for technical assistance with remediation

Evidence notes

CISA ICS advisory ICSA-24-270-05 (Update A, 2024-10-17) documents this vulnerability with CVSS 3.1 score 4.3 (Medium). The advisory confirms affected versions through 1.9.12 and remediation in version 2.0.7 or greater.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-45838 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-45838

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-45838 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-45838

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-270-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-05

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.