Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in goTenna Pro App for iOS and goTenna Pro App for Android - CVE-2024-47126

 

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in goTenna Pro App for iOS and goTenna Pro App for Android - CVE-2024-47126

Published: September 30, 2024


Vulnerability identifier: #VU97774
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47126
CWE-ID: CWE-338
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the affected application does not use SecureRandom when generating its cryptographic keys. A remote attacker on the local network can gain unauthorized access to sensitive information on the system.


Affected software

goTenna Pro App for iOS
goTenna Pro App for Android

How to mitigate CVE-2024-47126

Install updates from vendor's website.

goTenna Pro App for Android - update to 2.0.3

External References

Related Security Bulletins