Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fg6p-6vjg-95r5

Опубликовано: 26 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 6
CVSS3: 3.1

Описание

In the goTenna Pro there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing gotenna mesh networks. This vulnerability can be exploited if the device is being used in a unencrypted environment or if the cryptography has already been compromised.

In the goTenna Pro there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing gotenna mesh networks. This vulnerability can be exploited if the device is being used in a unencrypted environment or if the cryptography has already been compromised.

EPSS

Процентиль: 18%
0.00056
Низкий

6 Medium

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-1390
CWE-287

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

In the goTenna Pro App there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the device is being used in an unencrypted environment or if the cryptography has already been compromised. It is advised to share encryption keys via QR scanning for higher security operations and update your app to the current release for enhanced encryption protocols.

EPSS

Процентиль: 18%
0.00056
Низкий

6 Medium

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-1390
CWE-287