Cleartext transmission of sensitive information in goTenna Pro App for iOS and goTenna Pro App for Android - CVE-2024-47124
Published: September 30, 2024
Vulnerability identifier: #VU97772
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47124
CWE-ID: CWE-319
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the affected pplication does not encrypt the callsigns of its users. A remote attacker with ability to intercept network traffic can reveal information about the users.
Affected software
goTenna Pro App for iOS
goTenna Pro App for Android
goTenna Pro App for Android
How to mitigate CVE-2024-47124
Install update from vendor's website.
goTenna Pro App for Android - update to 2.0.3