← Back to home
ICSA-24-270-05  ·  Published 2024-10-17  ·  View on CISA ICS-CERT ↗

goTenna Pro ATAK Plugin (Update A)

CVSS 6.5 MEDIUM

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to compromise the confidentiality and integrity of the communications between the affected devices.

Remediations

  • goTenna recommends that users mitigate these vulnerabilities by performing the following updates:
  • ATAK Plugin: v2.0.7 or greater
  • goTenna recommends that users follow these mitigations:
  • General Mitigations for All Users/Clients
  • Use Discreet Callsigns and Key Names: Choose callsigns and key names that do not disclose sensitive information, such as your location, team size, or team name. Avoid using any identifiers that could inadvertently reveal your location or the composition of your team.
  • Secure End-User Devices: Implement strong security measures on all end-user devices, including the use of encryption and ensuring regular software updates.
  • Follow Key Rotation Best Practices: Regularly rotate encryption keys according to industry best practices to maintain ongoing security.
  • Pro-Specific Mitigations
  • Share Encryption Keys via QR Code: Utilize QR codes, similar to ATAK, for the secure exchange of encryption keys.
  • Secure Broadcasting: When broadcasting, ensure you are in a secured area and transmit the key at a reduced power of 0.5 Watts to limit exposure.
  • Leverage Layered Encryption: Implement layered encryption keys to securely manage communications, whether interacting with individuals or teams.
  • If you have any questions please contact [email protected]
  • goTenna recommends that users Follow their secure operating best practices.

Affected Vendors

goTenna

Affected Products (1)

goTenna · goTenna Pro ATAK Plugin <=1.9.12

Affected Sectors

Communications, Government Services and Facilities

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more