CVE-2024-47127
Weak Authentication in goTenna Pro
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
26 Sep 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In the goTenna Pro App there is a vulnerability that makes it possible
to inject any custom message with any GID and Callsign using a software
defined radio in existing goTenna mesh networks. This vulnerability can
be exploited if the device is being used in an unencrypted environment
or if the cryptography has already been compromised. It is advised to
share encryption keys via QR scanning for higher security operations and
update your app to the current release for enhanced encryption
protocols.
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
goTenna · ProWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →