In the goTenna Pro App there is a vulnerability that makes it possible
to inject any custom message with any GID and Callsign using a software
defined radio in existing goTenna mesh networks. This vulnerability can
be exploited if the device is being used in an unencrypted environment
or if the cryptography has already been compromised. It is advised to
share encryption keys via QR scanning for higher security operations and
update your app to the current release for enhanced encryption
protocols.
References
Link | Resource |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
History
17 Oct 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) In the goTenna Pro App there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the device is being used in an unencrypted environment or if the cryptography has already been compromised. It is advised to share encryption keys via QR scanning for higher security operations and update your app to the current release for enhanced encryption protocols. |
07 Oct 2024, 18:02
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:android:*:* |
07 Oct 2024, 14:17
Type | Values Removed | Values Added |
---|---|---|
First Time |
Gotenna
Gotenna gotenna Pro |
|
CPE | cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:*:*:* | |
References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04 - Third Party Advisory, US Government Resource | |
CWE | CWE-287 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.1 |
30 Sep 2024, 12:46
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
26 Sep 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-26 18:15
Updated : 2024-10-17 18:15
NVD link : CVE-2024-47127
Mitre link : CVE-2024-47127
CVE.ORG link : CVE-2024-47127
JSON object : View
Products Affected
gotenna
- gotenna_pro