CVE-2024-47126

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Sep 26, 2024
Updated: Oct 17, 2024
CWE ID 338

Summary

CVE-2024-47126: The goTenna Pro App is found to be vulnerable due to its use of an insecure random number generator for generating passwords when sharing cryptographic keys over RF. Attackers with the ability to intercept these broadcasted encryption keys can take advantage of this weakness to brute force the password, posing a significant security risk. Users are strongly advised to avoid broadcasting encryption keys and instead opt for sharing them via local QR codes to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share