CVE-2024-7543 is a heap-based buffer overflow vulnerability in oFono's SimToolKit, affecting oFono_project oFono. This flaw, stemming from improper validation of user-supplied data during STK command PDU parsing, allows a local attacker to achieve privilege escalation and execute arbitrary code in the context of the service account. Rated 7.8 HIGH (CVSSv3.1), exploitation requires prior code execution on the target modem. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3CPE matchmatch criteria | cpe:2.3:a:ofono_project:ofono:2.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.