Metrics
Affected Vendors & Products
Thu, 17 Oct 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The goTenna Pro series does not use SecureRandom when generating its cryptographic keys. The random function in use is not suitable for cryptographic use. | The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF. This only applies to the optional broadcast of an encryption key, so it is advised to share the key with local QR code for higher security operations. |
Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 07 Oct 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:android:*:* cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:iphone_os:*:* |
Mon, 07 Oct 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gotenna gotenna Pro
|
|
CPEs | cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gotenna gotenna Pro
|
|
Metrics |
cvssV3_1
|
Thu, 26 Sep 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gotenna
Gotenna pro App |
|
CPEs | cpe:2.3:a:gotenna:pro_app:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gotenna
Gotenna pro App |
|
Metrics |
ssvc
|
Thu, 26 Sep 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The goTenna Pro series does not use SecureRandom when generating its cryptographic keys. The random function in use is not suitable for cryptographic use. | |
Title | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in goTenna Pro | |
Weaknesses | CWE-338 | |
References |
| |
Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: icscert
Published: 2024-09-26T17:26:26.643Z
Updated: 2024-10-17T17:33:31.127Z
Reserved: 2024-09-18T21:32:27.325Z
Link: CVE-2024-47126
Updated: 2024-09-26T18:25:56.496Z
Status : Modified
Published: 2024-09-26T18:15:09.553
Modified: 2024-10-17T18:15:06.323
Link: CVE-2024-47126
No data.