SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-47126

The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF.

HIGH 7.1EPSS 0.24%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF. This only applies to the optional broadcast of an encryption key, so it is advised to share the key with local QR code for higher security operations.

CVSS 4.0
7.1 HIGHCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.24% probability · 15th percentile
CISA KEV
Not listed
Weakness
CWE-338
Affected
gotenna/gotenna pro
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.