CVE-2024-7545 is a heap-based buffer overflow vulnerability in oFono's SimToolKit, specifically affecting the parsing of STK command PDUs, which allows local privilege escalation. An attacker with initial code execution on the target modem can exploit this flaw due to improper validation of user-supplied data length, leading to arbitrary code execution in the context of the service account. Rated 7.8 HIGH on CVSS, this vulnerability has a low attack complexity and can result in high impact to confidentiality, integrity, and availability. Currently, there is no public exploit code available, nor is it known to be actively exploited, with minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3CPE matchmatch criteria | cpe:2.3:a:ofono_project:ofono:2.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.