The goTenna Pro App does not use SecureRandom when generating passwords
for sharing cryptographic keys. The random function in use makes it
easier for attackers to brute force this password if the broadcasted
encryption key is captured over RF. This only applies to the optional
broadcast of an encryption key, so it is advised to share the key with
local QR code for higher security operations.
References
Link | Resource |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
History
17 Oct 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF. This only applies to the optional broadcast of an encryption key, so it is advised to share the key with local QR code for higher security operations. |
07 Oct 2024, 18:02
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:android:*:* |
07 Oct 2024, 14:27
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
First Time |
Gotenna
Gotenna gotenna Pro |
|
CPE | cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:*:*:* | |
References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04 - Third Party Advisory, US Government Resource |
30 Sep 2024, 12:46
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
26 Sep 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-26 18:15
Updated : 2024-10-17 18:15
NVD link : CVE-2024-47126
Mitre link : CVE-2024-47126
CVE.ORG link : CVE-2024-47126
JSON object : View
Products Affected
gotenna
- gotenna_pro
CWE
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)