CVE-2024-47123

MEDIUM

goTenna Pro App - Info Disclosure

Title source: llm
STIX 2.1

Description

The goTenna Pro App uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message. It is recommended to continue to use encryption in the app and update to the current release for more secure operations.

Scores

CVSS v3 5.3
EPSS 0.0005
EPSS Percentile 16.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-353 CWE-345
Status published
Products (2)
gotenna/gotenna_pro < 1.6.1
gotenna/gotenna_pro < 2.0.3
Published Sep 26, 2024
Tracked Since Feb 18, 2026