#VU97770 Insecure Storage of Sensitive Information in goTenna Pro App for iOS and goTenna Pro App for Android - CVE-2024-47122

 

#VU97770 Insecure Storage of Sensitive Information in goTenna Pro App for iOS and goTenna Pro App for Android - CVE-2024-47122

Published: September 30, 2024


Vulnerability identifier: #VU97770
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-47122
CWE-ID: CWE-922
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
goTenna Pro App for iOS
goTenna Pro App for Android
Software vendor:
goTenna

Description

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to the encryption keys are stored along with a static IV on the device. An attacker with physical access can decrypt all encrypted communications that include P2P, Group, and broadcast messages that use these keys.


Remediation

Install updates from vendor's website.

External links