Описание
The goTenna Pro App uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message. It is recommended to continue to use encryption in the app and update to the current release for more secure operations.
Ссылки
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 1.6.1 (включая)Версия до 2.0.3 (исключая)
Одно из
cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:android:*:*
EPSS
Процентиль: 17%
0.00054
Низкий
5.3 Medium
CVSS3
3.1 Low
CVSS3
Дефекты
CWE-353
CWE-345
Связанные уязвимости
github
больше 1 года назад
The goTenna Pro series use AES CTR mode for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to any attacker that can access the message.
EPSS
Процентиль: 17%
0.00054
Низкий
5.3 Medium
CVSS3
3.1 Low
CVSS3
Дефекты
CWE-353
CWE-345