Gotenna Pro
Vendor:
First CVE: Sep 26, 2024 · Active for 1 year
10
Total CVEs
More Total CVEs than 88% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Gotenna Pro over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 26, 2024
21 months ago
Most Recent CVE
Sep 26, 2024
668 days ago
CVE Severity & Scoring
Gotenna Pro10 CVEs
20%
70%
10%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network10 (100.0%)
Attack Complexity
Low7 (70.0%)
High3 (30.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None10 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-47126HIGH The goTenna Pro App does not use SecureRandom when generating passwords
for sharing cryptographic keys. The random function in use makes it
easier for attackers to brute force th | Sep 26, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-47130MEDIUM The goTenna Pro App allows unauthenticated attackers to remotely update
the local public keys used for P2P and group messages. It is advised to
update your app to the current rel | Sep 26, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-47122MEDIUM In the goTenna Pro App, the encryption keys are stored along with a
static IV on the End User Device (EUD). This allows for complete
decryption of keys stored on the EUD if physi | Sep 26, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-47124MEDIUM The goTenna Pro App does not encrypt callsigns in messages. It is
recommended to not use sensitive information in callsigns when using
this and previous versions of the app and u | Sep 26, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-47125MEDIUM The goTenna Pro App does not authenticate public keys which allows an
unauthenticated attacker to manipulate messages. It is advised to update
your app to the current release for | Sep 26, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-47121MEDIUM The goTenna Pro App uses a weak password for sharing encryption keys via
the key broadcast method. If the broadcasted encryption key is captured
over RF, and password is cracked | Sep 26, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-47129MEDIUM The goTenna Pro App does not inject extra characters into broadcasted
frames to obfuscate the length of messages. This makes it possible to
tell the length of the payload regardl | Sep 26, 2024 | 4.3 | 15 | NO | NO |
CVE-2024-47128MEDIUM The goTenna Pro App encryption key name is always sent unencrypted when
the key is shared over RF through a broadcast message. It is advised to
share the encryption key via local | Sep 26, 2024 | 4.3 | 15 | NO | NO |
In the goTenna Pro App there is a vulnerability that makes it possible
to inject any custom message with any GID and Callsign using a software
defined radio in existing goTenna m | Sep 26, 2024 | 3.1 | 13 | NO | NO |
The goTenna Pro App uses AES CTR type encryption for short, encrypted
messages without any additional integrity checking mechanisms. This
leaves messages malleable to an attacker | Sep 26, 2024 | 3.1 | 13 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Gotenna Pro
Top CWEs
Versions
No cataloged versions.