Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9cgq-h66g-4xhp

Опубликовано: 02 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phone number unless they specifically opt out. A phone number is very sensitive information because it can be tied back to individuals. The app does not encrypt the GID in messages.

An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phone number unless they specifically opt out. A phone number is very sensitive information because it can be tied back to individuals. The app does not encrypt the GID in messages.

EPSS

Процентиль: 4%
0.00019
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 4.3
nvd
9 месяцев назад

An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phone number unless they specifically opt out. A phone number is very sensitive information because it can be tied back to individuals. The app does not encrypt the GID in messages.

EPSS

Процентиль: 4%
0.00019
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-319