CVE-2024-7544 is a heap-based buffer overflow vulnerability in oFono's SimToolKit, specifically affecting the ofono_project ofono product. This flaw allows a local attacker to achieve privilege escalation and execute arbitrary code by exploiting improper validation of user-supplied data lengths during STK command PDU parsing. With a CVSS score of 7.8 (High), successful exploitation grants an attacker high confidentiality, integrity, and availability impact, though it requires initial code execution on the target modem. Currently, there is no known public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3CPE matchmatch criteria | cpe:2.3:a:ofono_project:ofono:2.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.