CVE-2022-24403 is a medium-severity vulnerability affecting TETRA TA61 identity encryption, specifically in midnightblue tetra products. It allows an attacker to recover a 64-bit encryption key by analyzing three known encrypted/unencrypted identity pairs. This enables an adversary to encrypt or decrypt arbitrary identities. The vulnerability has a CVSS score of 4.3 (Medium) with an attack vector of Adjacent Network, low attack complexity, and no user interaction required, leading to a potential impact of limited confidentiality. While it has a low EPSS and FAUCET Risk Score, it could expose military communications and industrial systems. Currently, there is no public exploit code available for CVE-2022-24403, and it is not listed in CISA's Known Exploited Vulnerabilities catalog. Community discussion and media coverage are minimal, suggesting limited active exploitation or widespread awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:midnightblue:tetra\:burst:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.