The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group messages. It is advised to update your app to the current release for enhanced encryption protocols.
History

Thu, 17 Oct 2024 17:45:00 +0000

Type Values Removed Values Added
Description The goTenna Pro series allows unauthenticated attackers to remotely update the local public keys used for P2P and Group messages. The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group messages. It is advised to update your app to the current release for enhanced encryption protocols.
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 07 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:*:*:* cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:android:*:*
cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:iphone_os:*:*

Fri, 04 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Gotenna gotenna Pro
CPEs cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:*:*:*
Vendors & Products Gotenna gotenna Pro
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Thu, 26 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Gotenna
Gotenna pro App
CPEs cpe:2.3:a:gotenna:pro_app:*:*:*:*:*:*:*:*
Vendors & Products Gotenna
Gotenna pro App
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 26 Sep 2024 17:45:00 +0000

Type Values Removed Values Added
Description The goTenna Pro series allows unauthenticated attackers to remotely update the local public keys used for P2P and Group messages.
Title Missing Authentication for Critical Function in goTenna Pro
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-09-26T17:30:52.751Z

Updated: 2024-10-17T17:42:43.163Z

Reserved: 2024-09-18T21:32:27.325Z

Link: CVE-2024-47130

cve-icon Vulnrichment

Updated: 2024-09-26T18:13:26.531Z

cve-icon NVD

Status : Modified

Published: 2024-09-26T18:15:10.040

Modified: 2024-10-17T18:15:07.130

Link: CVE-2024-47130

cve-icon Redhat

No data.