PT-2024-32418 · Gotenna · Gotenna Pro X+2

Clayton Smith

+2

·

Published

2024-09-26

·

Updated

2024-10-17

·

CVE-2024-47123

CVSS v3.1

5.3

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions goTenna Pro App (affected versions not specified) goTenna Pro X (affected versions not specified) goTenna Pro X2 (affected versions not specified)
Description The goTenna Pro series uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message.
Recommendations Update to the current release for more secure operations. As a temporary workaround, consider using additional integrity checking mechanisms to minimize the risk of exploitation. Restrict access to sensitive messages to minimize the risk of exploitation until a more secure version is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2024-47123

Affected Products

Gotenna Pro App
Gotenna Pro X
Gotenna Pro X2