CVE-2024-47123 - CVE House
Back to Database
Status published Medium CVE-2024-47123

Missing Support for Integrity Check in goTenna Pro

Vulnerability Description

The goTenna Pro App uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message. It is recommended to continue to use encryption in the app and update to the current release for more secure operations.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-47123

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Erwin Karincic, Clayton Smith, and Dale Wooden reported this these vulnerabilities to CISA.

Affected Vendor

Affected Software

Pro
Vulnerable Versions:
0

Timeline

Official Publish: September 26th, 2024
Last Modified: November 21st, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.