Attackers can Remotely Update Local Public Keys for P2P and Group Messages
CVE-2024-47130
6.5MEDIUM
What is CVE-2024-47130?
The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group messages. It is advised to update your app to the current release for enhanced encryption protocols.
Affected Version(s)
Pro 0 <= 1.61
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Erwin Karincic, Clayton Smith, and Dale Wooden reported this these vulnerabilities to CISA.