CVE-2024-41722
Last modified
CVE-2024-41722 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the device is being used in an unencrypted environment or if the cryptography has already been compromised. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the device is being used in an unencrypted environment or if the cryptography has already been compromised. It is advised to use encryption shared with local QR code for higher security operations.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gotenna | Gotenna | < 2.0.7 |
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-05Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-41722?
How severe is CVE-2024-41722?
How do I fix CVE-2024-41722?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-41717Kieback & Peter's DDC4000 series is vulnerable to a path tra…9.8
- CVE-2024-41718Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID. Consul…
- CVE-2024-41719When generating QKView of BIG-IP Next instance from the BIG-…5.5
- CVE-2024-4172A vulnerability classified as problematic was found in idcCM…4.3
- CVE-2024-41720Incorrect permission assignment for critical resource issue …8
- CVE-2024-41721An insufficient boundary validation in the USB code could le…8.1
- CVE-2024-41723Undisclosed requests to BIG-IP iControl REST can lead to inf…4.3
- CVE-2024-41724Improper Certificate Validation (CWE-295) in the Gallagher C…8.7
- CVE-2024-41725ProGauge MAGLINK LX CONSOLE does not have sufficient filteri…6.1
- CVE-2024-41726Path traversal vulnerability exists in SKYSEA Client View Ve…7.5
- CVE-2024-41727In BIG-IP tenants running on r2000 and r4000 series hardware…7.5
- CVE-2024-41728Due to missing authorization check, SAP NetWeaver Applicatio…2.7
Are you affected by CVE-2024-41722?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
