Insecure Storage of Sensitive Information in goTenna Pro App for iOS and goTenna Pro App for Android - CVE-2024-47122

 

Insecure Storage of Sensitive Information in goTenna Pro App for iOS and goTenna Pro App for Android - CVE-2024-47122

Published: September 30, 2024


Vulnerability identifier: #VU97770
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47122
CWE-ID: CWE-922
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to the encryption keys are stored along with a static IV on the device. An attacker with physical access can decrypt all encrypted communications that include P2P, Group, and broadcast messages that use these keys.


Affected software

goTenna Pro App for iOS
goTenna Pro App for Android

How to mitigate CVE-2024-47122

Install updates from vendor's website.

goTenna Pro App for Android - update to 2.0.3

External References

Related Security Bulletins