The goTenna Pro App encryption key name is always sent unencrypted when the key is shared over RF through a broadcast message. It is advised to share the encryption key via local QR for higher security operations.
History

Thu, 17 Oct 2024 17:45:00 +0000

Type Values Removed Values Added
Description The goTenna Pro broadcast key name is always sent unencrypted and could reveal the location of operation. The goTenna Pro App encryption key name is always sent unencrypted when the key is shared over RF through a broadcast message. It is advised to share the encryption key via local QR for higher security operations.

Mon, 07 Oct 2024 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:*:*:* cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:android:*:*
cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:iphone_os:*:*

Fri, 04 Oct 2024 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Gotenna gotenna Pro
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:*:*:*
Vendors & Products Gotenna gotenna Pro
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Thu, 26 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Gotenna
Gotenna pro App
CPEs cpe:2.3:a:gotenna:pro_app:*:*:*:*:*:*:*:*
Vendors & Products Gotenna
Gotenna pro App
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Sep 2024 17:45:00 +0000

Type Values Removed Values Added
Description The goTenna Pro broadcast key name is always sent unencrypted and could reveal the location of operation.
Title Insertion of Sensitive Information Into Sent Data in goTenna Pro
Weaknesses CWE-201
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-09-26T17:28:32.604Z

Updated: 2024-10-17T17:37:51.475Z

Reserved: 2024-09-18T21:32:27.325Z

Link: CVE-2024-47128

cve-icon Vulnrichment

Updated: 2024-09-26T18:22:56.395Z

cve-icon NVD

Status : Modified

Published: 2024-09-26T18:15:09.783

Modified: 2024-10-17T18:15:06.727

Link: CVE-2024-47128

cve-icon Redhat

No data.