CVE-2024-47126

MEDIUM

goTenna Pro App - Info Disclosure

Title source: llm
STIX 2.1

Description

The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF. This only applies to the optional broadcast of an encryption key, so it is advised to share the key with local QR code for higher security operations.

Scores

CVSS v3 6.5
EPSS 0.0008
EPSS Percentile 23.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-338
Status published
Products (2)
gotenna/gotenna_pro < 1.6.1
gotenna/gotenna_pro < 2.0.3
Published Sep 26, 2024
Tracked Since Feb 18, 2026