Weak password requirements in goTenna Pro App for Android and goTenna Pro App for iOS - CVE-2024-47121
Published: September 30, 2024
Vulnerability identifier: #VU97769
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47121
CWE-ID: CWE-521
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to weak password requirements for the QR broadcast message. A remote attacker on the local network can decrypt the QR broadcast message and use it to decrypt all future and past messages sent via encrypted broadcast.
Affected software
goTenna Pro App for Android
goTenna Pro App for iOS
goTenna Pro App for iOS
How to mitigate CVE-2024-47121
Install updates from vendor's website.
goTenna Pro App for Android - update to 2.0.3