The goTenna Pro App does not inject extra characters into broadcasted
frames to obfuscate the length of messages. This makes it possible to
tell the length of the payload regardless of the encryption used.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Oct 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The goTenna Pro has a payload length vulnerability that makes it possible to tell the length of the payload regardless of the encryption used. | The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payload regardless of the encryption used. |
Mon, 07 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:android:*:* cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:iphone_os:*:* |
Fri, 04 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gotenna gotenna Pro
|
|
Weaknesses | CWE-203 | |
CPEs | cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gotenna gotenna Pro
|
|
Metrics |
cvssV3_1
|
Thu, 26 Sep 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gotenna
Gotenna pro App |
|
CPEs | cpe:2.3:a:gotenna:pro_app:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gotenna
Gotenna pro App |
|
Metrics |
ssvc
|
Thu, 26 Sep 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The goTenna Pro has a payload length vulnerability that makes it possible to tell the length of the payload regardless of the encryption used. | |
Title | Observable Response Discrepancy in goTenna Pro | |
Weaknesses | CWE-204 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2024-09-26T17:30:12.759Z
Updated: 2024-10-17T17:40:06.968Z
Reserved: 2024-09-18T21:32:27.325Z
Link: CVE-2024-47129
Vulnrichment
Updated: 2024-09-26T18:14:30.912Z
NVD
Status : Modified
Published: 2024-09-26T18:15:09.913
Modified: 2024-10-17T18:15:06.930
Link: CVE-2024-47129
Redhat
No data.