Improper restriction of communication channel to intended endpoints in goTenna Pro App for iOS and goTenna Pro App for Android - CVE-2024-47125
Published: September 30, 2024
Vulnerability identifier: #VU97773
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47125
CWE-ID: CWE-923
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected application does not authenticate public keys. A remote attacker on the local network can intercept and manipulate messages.
Affected software
goTenna Pro App for iOS
goTenna Pro App for Android
goTenna Pro App for Android
How to mitigate CVE-2024-47125
Install updates from vendor's website.
goTenna Pro App for Android - update to 2.0.3