#VU97770 Insecure Storage of Sensitive Information in goTenna Pro App for iOS and goTenna Pro App for Android - CVE-2024-47122
Published: September 30, 2024
goTenna Pro App for iOS
goTenna Pro App for Android
goTenna
Description
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to the encryption keys are stored along with a static IV on the device. An attacker with physical access can decrypt all encrypted communications that include P2P, Group, and broadcast messages that use these keys.