PT-2024-32422 · Gotenna · Gotenna Pro X+2

Clayton Smith

+2

·

Published

2024-09-26

·

Updated

2024-10-17

·

CVE-2024-47127

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions goTenna Pro App (affected versions not specified) goTenna Pro X goTenna Pro X2
Description The issue allows an attacker to inject custom messages with any GID and Callsign into existing goTenna mesh networks using a software-defined radio. This can be exploited in unencrypted environments or if the cryptography has been compromised.
Recommendations For goTenna Pro App, update the app to the current release for enhanced encryption protocols. For goTenna Pro X and goTenna Pro X2, update the app to the current release for enhanced encryption protocols. As a temporary workaround, consider sharing encryption keys via QR scanning for higher security operations.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-47127

Affected Products

Gotenna Pro App
Gotenna Pro X
Gotenna Pro X2