HIGH🇵🇱 Wersja polska

CVE-2024-47130

CVSS 8.7v4.0pub. 2024-09-26upd. 2024-10-17

The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group messages. It is advised to update your app to the current release for enhanced encryption protocols.

CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Gotenna Pro

    APP
    Gotenna
    ≤ 1.6.1< 2.0.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-47126HIGH7.1same product

The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The r...

CVE-2024-47125HIGH7.6same product

The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate ...

CVE-2024-47123MEDIUM6.0same product

The goTenna Pro App uses AES CTR type encryption for short, encrypted messages without any additional integri...

CVE-2024-47129MEDIUM5.3same product

The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messa...

CVE-2024-47122MEDIUM5.1same product

In the goTenna Pro App, the encryption keys are stored along with a static IV on the End User Device (EUD). T...