|
251501
|
6.5 |
MEDIUM
Adjacent
|
gotenna
|
gotenna
|
The goTenna Pro ATAK plugin uses a weak password for sharing encryption
keys via the key broadcast method. If the broadcasted encryption key is
captured over RF, and password is cracked via brute f…
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2024-45374
|
2024-10-18 02:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251502
|
6.5 |
MEDIUM
Adjacent
|
gotenna
|
gotenna
|
The goTenna Pro ATAK Plugin uses AES CTR type encryption for short,
encrypted messages without any additional integrity checking mechanisms.
This leaves messages malleable to an attacker that can a…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2024-43108
|
2024-10-18 02:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251503
|
4.3 |
MEDIUM
Adjacent
|
gotenna
|
gotenna
|
The goTenna Pro ATAK Plugin encryption key name is always sent
unencrypted when the key is sent over RF through a broadcast message. It
is advised to share the encryption key via local QR for highe…
|
NVD-CWE-Other
|
CVE-2024-41931
|
2024-10-18 02:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251504
|
6.5 |
MEDIUM
Adjacent
|
gotenna
|
gotenna
|
In the goTenna Pro ATAK Plugin there is a vulnerability that makes it
possible to inject any custom message with any GID and Callsign using a
software defined radio in existing goTenna mesh network…
|
NVD-CWE-Other
|
CVE-2024-41722
|
2024-10-18 02:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251505
|
4.3 |
MEDIUM
Adjacent
|
gotenna
|
atak_plugin
|
The goTenna Pro ATAK Plugin does not inject extra characters into
broadcasted frames to obfuscate the length of messages. This makes it
possible to tell the length of the payload regardless of the …
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2024-41715
|
2024-10-18 02:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251506
|
9.1 |
CRITICAL
Network
|
gradio_project
|
gradio
|
Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure communication** between the FRP (Fast Reverse Proxy) client and server when Gradio's `sh…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2024-47871
|
2024-10-18 02:11 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251507
|
7.5 |
HIGH
Network
|
gradio_project
|
gradio
|
Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio components, which allows arbitrary file leaks through the …
|
CWE-22
Path Traversal
|
CVE-2024-47868
|
2024-10-18 02:04 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251508
|
4.3 |
MEDIUM
Network
|
gradio_project
|
gradio
|
Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves data exposure due to the enable_monitoring flag not properly disabling monitoring when set to False…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2024-47168
|
2024-10-18 02:00 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251509
|
3.7 |
LOW
Network
|
gradio_project
|
gradio
|
Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **timing attack** in the way Gradio compares hashes for the `analytics_dashboard` function. Since…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2024-47869
|
2024-10-18 01:59 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251510
|
8.1 |
HIGH
Network
|
gradio_project
|
gradio
|
Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **race condition** in the `update_root_in_config` function, allowing an attacker to modify the `r…
|
CWE-362
Race Condition
|
CVE-2024-47870
|
2024-10-18 01:57 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|