Metrics
Affected Vendors & Products
Thu, 17 Oct 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In the goTenna Pro there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing gotenna mesh networks. This vulnerability can be exploited if the device is being used in a unencrypted environment or if the cryptography has already been compromised. | In the goTenna Pro App there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the device is being used in an unencrypted environment or if the cryptography has already been compromised. It is advised to share encryption keys via QR scanning for higher security operations and update your app to the current release for enhanced encryption protocols. |
Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 07 Oct 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:android:*:* cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:iphone_os:*:* |
Mon, 07 Oct 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gotenna gotenna Pro
|
|
Weaknesses | CWE-287 | |
CPEs | cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gotenna gotenna Pro
|
|
Metrics |
cvssV3_1
|
Thu, 26 Sep 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gotenna
Gotenna pro App |
|
CPEs | cpe:2.3:a:gotenna:pro_app:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gotenna
Gotenna pro App |
|
Metrics |
ssvc
|
Thu, 26 Sep 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In the goTenna Pro there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing gotenna mesh networks. This vulnerability can be exploited if the device is being used in a unencrypted environment or if the cryptography has already been compromised. | |
Title | Weak Authentication in goTenna Pro | |
Weaknesses | CWE-1390 | |
References |
| |
Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: icscert
Published: 2024-09-26T17:27:35.188Z
Updated: 2024-10-17T17:35:50.706Z
Reserved: 2024-09-18T21:32:27.325Z
Link: CVE-2024-47127
Updated: 2024-09-26T18:24:42.216Z
Status : Modified
Published: 2024-09-26T18:15:09.667
Modified: 2024-10-17T18:15:06.537
Link: CVE-2024-47127
No data.