PatchSiren cyber security CVE debrief
CVE-2024-47124 goTenna CVE debrief
goTenna Pro App versions 1.6.1 and earlier fail to encrypt callsigns in messages, exposing potentially sensitive identifier information to network observers within radio range. The vulnerability stems from cleartext transmission of callsign metadata even when message encryption is enabled. CISA published this advisory on September 26, 2024, with an update on October 17, 2024 revising the vulnerability overview, affected products, and mitigations sections. goTenna has released patched versions (Android Pro v2.0.3+, iOS Pro v2.0.3+) that implement AES-256 encryption for callsigns during encrypted operations. The CVSS 3.1 vector (AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) reflects adjacent network attack vector with low attack complexity and low confidentiality impact.
- Vendor
- goTenna
- Product
- Pro
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-09-26
- Original CVE updated
- 2024-10-17
- Advisory published
- 2024-09-26
- Advisory updated
- 2024-10-17
Who should care
Organizations using goTenna Pro X and Pro X2 devices for tactical, emergency response, or field operations where callsign confidentiality protects personnel safety, operational security, or team composition details. Particularly relevant for public safety, military, and disaster response users whose callsigns may reveal sensitive organizational information.
Technical summary
The goTenna Pro App transmits callsigns in cleartext within message metadata, even when message content encryption is active. This information disclosure vulnerability allows adjacent network attackers (within radio transmission range) to harvest callsigns without authentication. The issue affects app versions through 1.6.1. Resolution in v2.0.3+ applies AES-256 encryption to callsigns during encrypted operations, closing the metadata exposure gap.
Defensive priority
medium
Recommended defensive actions
- Update goTenna Pro App to version 2.0.3 or later on Android and iOS devices to enable AES-256 encryption for callsigns
- Avoid using sensitive information in callsigns and key names until update is applied; do not include location, team size, or team identifiers
- Implement strong security measures on end-user devices including encryption and regular software updates
- Rotate encryption keys regularly according to industry best practices
- Use QR codes for secure exchange of encryption keys rather than broadcast transmission
- When broadcasting is necessary, operate from secured areas at reduced power (0.5 Watts) to limit exposure
- Implement layered encryption keys for managing communications with individuals and teams
- Contact goTenna Pro support at [email protected] for assistance with secure operating procedures
Evidence notes
Advisory ICSA-24-270-04 confirms affected product as goTenna Pro App ≤1.6.1. Remediation guidance specifies v2.0.3 or greater for both Android and iOS platforms. Vendor contact: [email protected].
Sources and references
Verified primary and authoritative sources
-
CVE-2024-47124 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-47124
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-47124 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-47124
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-270-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.