CVE-2024-47121
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2024-47121: The goTenna Pro App, which allows users to communicate off-grid, is found to have a vulnerability in its key broadcast method. The app uses a weak password to encrypt keys shared via RF. If an attacker intercepts the broadcasted encryption key and successfully cracks the password through brute force, they can decrypt all future and past encrypted messages associated with that key. This issue is only pertinent when the key is shared via RF and does not affect local QR encryption key sharing. To enhance security, it is advised to utilize the local QR method for key exchange on this and previous versions of the app.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Pro Series