The goTenna Pro App uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and use it to decrypt all future and past messages sent via encrypted broadcast with that particular key. This only applies when the key is broadcasted over RF. This is an optional feature, so it is recommended to use local QR encryption key sharing for additional security on this and previous versions.
History

Fri, 01 Nov 2024 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:*:*:* cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:android:*:*
cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:iphone_os:*:*

Thu, 17 Oct 2024 17:30:00 +0000

Type Values Removed Values Added
Description The goTenna Pro series uses a weak password for the QR broadcast message. If the QR broadcast message is captured over RF it is possible to decrypt it and use it to decrypt all future and past messages sent via encrypted broadcast. The goTenna Pro App uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and use it to decrypt all future and past messages sent via encrypted broadcast with that particular key. This only applies when the key is broadcasted over RF. This is an optional feature, so it is recommended to use local QR encryption key sharing for additional security on this and previous versions.
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Mon, 07 Oct 2024 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Gotenna
Gotenna gotenna Pro
CPEs cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:*:*:*
Vendors & Products Gotenna
Gotenna gotenna Pro
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Thu, 26 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
Description The goTenna Pro series uses a weak password for the QR broadcast message. If the QR broadcast message is captured over RF it is possible to decrypt it and use it to decrypt all future and past messages sent via encrypted broadcast.
Title Weak Passwords Requirements in goTenna Pro
Weaknesses CWE-521
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-09-26T17:18:03.228Z

Updated: 2024-10-17T17:19:36.091Z

Reserved: 2024-09-18T21:32:27.324Z

Link: CVE-2024-47121

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-09-26T18:15:08.967

Modified: 2024-11-01T20:39:20.677

Link: CVE-2024-47121

cve-icon Redhat

No data.