PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-47125 goTenna CVE debrief

goTenna Pro App versions 1.6.1 and earlier fail to authenticate public keys, enabling unauthenticated attackers to manipulate messages in transit. The vulnerability stems from insufficient cryptographic verification, allowing adversaries within radio range to inject or alter communications without possessing valid credentials. CISA published this advisory on September 26, 2024, with an update on October 17, 2024, refining vulnerability details and mitigation guidance. The CVSS 3.1 score of 8.1 reflects high confidentiality and integrity impact with adjacent network access required. goTenna has released patched versions 2.0.3 for both Android and iOS platforms, which implement enhanced encryption protocols addressing the authentication gap.

Vendor
goTenna
Product
Pro
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2024-09-26
Original CVE updated
2024-10-17
Advisory published
2024-09-26
Advisory updated
2024-10-17

Who should care

Organizations using goTenna Pro X and Pro X2 devices for tactical, emergency, or off-grid communications, including public safety agencies, military units, disaster response teams, and private security operations relying on authenticated message integrity.

Technical summary

The goTenna Pro App's failure to validate public keys creates a cryptographic authentication bypass. An attacker within radio transmission range can exploit this to forge or modify messages without authentication, compromising message integrity and confidentiality. The attack requires adjacent network access (AV:A) but no privileges or user interaction, with low attack complexity. Remediation involves updating to version 2.0.3, which implements proper public key authentication within enhanced encryption protocols.

Defensive priority

HIGH

Recommended defensive actions

  • Update goTenna Pro App to version 2.0.3 or later on Android and iOS devices
  • Use discreet callsigns and key names that do not reveal location, team size, or operational details
  • Implement strong endpoint security measures including device encryption and regular software updates
  • Rotate encryption keys according to industry best practices
  • Exchange encryption keys via QR code rather than broadcast transmission
  • When broadcasting keys is necessary, operate from secured areas at reduced 0.5 Watt power
  • Apply layered encryption for communications with individuals and teams
  • Contact goTenna Pro support at [email protected] for technical assistance

Evidence notes

The source advisory confirms affected versions through CSAFPID-0001 (goTenna Pro App ≤1.6.1) and specifies remediation versions 2.0.3 or greater for both platforms.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-47125 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-47125

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-47125 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-47125

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-270-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.