Описание
The goTenna Pro App does not encrypt callsigns in messages. It is recommended to not use sensitive information in callsigns when using this and previous versions of the app and update your app to the current app version which uses AES-256 encryption for callsigns in encrypted operation.
Ссылки
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 1.6.1 (включая)Версия до 2.0.3 (исключая)
Одно из
cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:gotenna:gotenna_pro:*:*:*:*:*:android:*:*
EPSS
Процентиль: 7%
0.00026
Низкий
4.3 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-319
Связанные уязвимости
CVSS3: 6.5
github
больше 1 года назад
The goTenna pro series does not encrypt the callsigns of its users. These callsigns reveal information about the users and can also be leveraged for other vulnerabilities.
EPSS
Процентиль: 7%
0.00026
Низкий
4.3 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-319