PT-2024-32421 · Gotenna · Gotenna Pro X+2
Clayton Smith
+2
·
Published
2024-09-26
·
Updated
2024-10-17
·
CVE-2024-47126
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
goTenna Pro App (affected versions not specified)
goTenna Pro X (affected versions not specified)
goTenna Pro X2 (affected versions not specified)
Description
The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF. This issue only applies to the optional broadcast of an encryption key. For higher security operations, it is advised to share the key with a local QR code.
Recommendations
For goTenna Pro App, consider disabling the broadcast of encryption keys until a patch is available.
For goTenna Pro X, restrict access to the key sharing feature to minimize the risk of exploitation.
For goTenna Pro X2, avoid using the broadcasted encryption key until the issue is resolved.
As a temporary workaround, consider sharing keys with a local QR code for higher security operations.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gotenna Pro App
Gotenna Pro X
Gotenna Pro X2