Attackers can Remotely Update Local Public Keys for P2P and Group Messages
CVE-2024-47130

6.5MEDIUM

Key Information:

Vendor

Gotenna

Status
Vendor
CVE Published:
26 September 2024

What is CVE-2024-47130?

The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group messages. It is advised to update your app to the current release for enhanced encryption protocols.

Affected Version(s)

Pro 0 <= 1.61

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Erwin Karincic, Clayton Smith, and Dale Wooden reported this these vulnerabilities to CISA.
.