CVE-2024-47125

The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate messages. It is advised to update your app to the current release for enhanced encryption protocols.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:android:*:*

History

17 Oct 2024, 18:15

Type Values Removed Values Added
Summary (en) The goTenna Pro series does not authenticate public keys which allows an unauthenticated attacker to intercept and manipulate messages. (en) The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate messages. It is advised to update your app to the current release for enhanced encryption protocols.

07 Oct 2024, 17:57

Type Values Removed Values Added
CPE cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:*:*:* cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:android:*:*

04 Oct 2024, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-287
First Time Gotenna
Gotenna gotenna Pro
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04 - () https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04 - Third Party Advisory, US Government Resource
CPE cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:*:*:*

30 Sep 2024, 12:46

Type Values Removed Values Added
Summary
  • (es) La serie goTenna Pro no autentica claves públicas, lo que permite que un atacante no autenticado intercepte y manipule mensajes.

26 Sep 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-26 18:15

Updated : 2024-10-17 18:15


NVD link : CVE-2024-47125

Mitre link : CVE-2024-47125

CVE.ORG link : CVE-2024-47125


JSON object : View

Products Affected

gotenna

  • gotenna_pro
CWE
CWE-287

Improper Authentication

CWE-923

Improper Restriction of Communication Channel to Intended Endpoints