Insertion of Sensitive Information Into Sent Data in goTenna Pro App for iOS and goTenna Pro App for Android - CVE-2024-47128
Published: September 30, 2024
Vulnerability identifier: #VU97816
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47128
CWE-ID: CWE-201
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the broadcast key name is always sent unencrypted and can reveal the location of operation. A remote attacker on the local network can gain unauthorized access to sensitive information on the system.
Affected software
goTenna Pro App for iOS
goTenna Pro App for Android
goTenna Pro App for Android
How to mitigate CVE-2024-47128
Install updates from vendor's website.
goTenna Pro App for Android - update to 2.0.3