In the goTenna Pro App there is a vulnerability that makes it possible
to inject any custom message with any GID and Callsign using a software
defined radio in existing goTenna mesh networks. This vulnerability can
be exploited if the device is being used in an unencrypted environment
or if the cryptography has already been compromised. It is advised to
share encryption keys via QR scanning for higher security operations and
update your app to the current release for enhanced encryption
protocols.
References
Link | Resource |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
History
17 Oct 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
Summary | In the goTenna Pro App there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the device is being used in an unencrypted environment or if the cryptography has already been compromised. It is advised to share encryption keys via QR scanning for higher security operations and update your app to the current release for enhanced encryption protocols. |
07 Oct 2024, 18:02
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:android:*:* cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:iphone_os:*:* |
07 Oct 2024, 14:17
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04 - Third Party Advisory, US Government Resource | |
First Time |
Gotenna gotenna Pro
Gotenna |
|
CWE | CWE-287 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.1 |
CPE | cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:*:*:* |
26 Sep 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-26 18:15
Updated : 2024-10-17 18:15
NVD link : CVE-2024-47127
Mitre link : CVE-2024-47127
JSON object : View
Products Affected
gotenna
- gotenna_pro
CWE
CWE-287
Improper Authentication