Payload Length Vulnerability Affects goTenna Pro ATAK Plugin
CVE-2024-41715
What is CVE-2024-41715?
The goTenna Pro ATAK Plugin is vulnerable due to the lack of obfuscation techniques in its broadcasted frames. Specifically, the plugin does not inject extra characters into messages, allowing malicious actors to infer the actual length of the payloads. This vulnerability compromises the expected confidentiality provided by encryption, as attackers can determine the size of the transmitted data regardless of how securely it is encrypted. Proper measures should be implemented to enhance message obfuscation and safeguard sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Pro ATAK Plugin 0 <= 1.9.12
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
