CVE-2024-7546 is a heap-based buffer overflow vulnerability in oFono SimToolKit, affecting oFono_project oFono. This flaw allows a local attacker to achieve privilege escalation and execute arbitrary code by exploiting improper validation of user-supplied data length during STK command PDU parsing. The vulnerability has a CVSS score of 7.8 (High), indicating high impact on confidentiality, integrity, and availability, with low attack complexity and no user interaction required once initial access to the modem is gained. Currently, there is no public exploit code available, it is not listed in the KEV catalog, and it has received no community discussion or media coverage, suggesting a low immediate exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3CPE matchmatch criteria | cpe:2.3:a:ofono_project:ofono:2.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.