Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-47124


The goTenna Pro App does not encrypt callsigns in messages. It is recommended to not use sensitive information in callsigns when using this and previous versions of the app and update your app to the current app version which uses AES-256 encryption for callsigns in encrypted operation.


Published

2024-09-26T18:15:09.310

Last Modified

2024-10-17T18:15:05.900

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-319

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gotenna gotenna_pro ≤ 1.6.1 Yes
Application gotenna gotenna_pro < 2.0.3 Yes

References