The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payload regardless of the encryption used.
https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04
Published: 2024-09-26
Updated: 2024-10-17
Base Score: 3.3
Vector: CVSS2#AV:A/AC:L/Au:N/C:P/I:N/A:N
Severity: Low
Base Score: 4.3
Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity: Medium
Base Score: 5.3
Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Severity: Medium