{ "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", "CVE_data_meta": { "ID": "CVE-2024-47123", "ASSIGNER": "ics-cert@hq.dhs.gov", "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", "value": "The goTenna Pro App uses AES CTR type encryption for short, encrypted \nmessages without any additional integrity checking mechanisms. This \nleaves messages malleable to an attacker that can access the message. It\n is recommended to continue to use encryption in the app and update to \nthe current release for more secure operations." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-353 Missing Support for Integrity Check", "cweId": "CWE-353" } ] } ] }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "goTenna", "product": { "product_data": [ { "product_name": "Pro", "version": { "version_data": [ { "version_affected": "<=", "version_name": "0", "version_value": "1.61" } ] } } ] } } ] } }, "references": { "reference_data": [ { "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04", "refsource": "MISC", "name": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04" } ] }, "generator": { "engine": "Vulnogram 0.2.0" }, "source": { "advisory": "ICSA-24-270-04", "discovery": "EXTERNAL" }, "work_around": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "
goTenna recommends that users follow these mitigations:
\nGeneral Mitigations for All Users/Clients
\nPro-Specific Mitigations
\nIf you have any questions please contact prosupport@gotenna.com.
\ngoTenna recommends users follow their secure operating best practices
\n\n