Security Advisory

CVE-2024-47126

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-09-26 17:26:26
Last updated 2024-10-17 17:33:31
Assigner icscert
State PUBLISHED

Description

The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF. This only applies to the optional broadcast of an encryption key, so it is advised to share the key with local QR code for higher security operations.