← volver
CVE-2024-47123mediumCWE-353

Missing Support for Integrity Check in goTenna Pro

13Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 6epss 0.1%
probabilidad de explotación
0.1%top 100% de las CVE
explotación observada
noninguna fuente lo reporta
The goTenna Pro App uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message. It is recommended to continue to use encryption in the app and update to the current release for more secure operations.
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
goTenna · Pro