CVE-2024-45838

EUVD-2024-41625
The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It 
is advised to not use sensitive information in callsigns when using this
 and previous versions of the plugin. Update to current plugin version 
which uses AES-256 encryption for callsigns in encrypted operation
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
icscertCNA
4.3 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Affected Products (NVD)
VendorProductVersion
gotennagotenna
𝑥
< 2.0.7
𝑥
= Vulnerable software versions