CVE-2024-7547 is a stack-based buffer overflow vulnerability in the oFono SMS Decoder, affecting oFono Project's oFono software. This flaw allows local attackers to achieve privilege escalation and execute arbitrary code by exploiting improper validation of user-supplied SMS PDU data. Rated 7.8 HIGH on CVSS, it requires prior code execution on the target modem, but once exploited, grants code execution in the context of the service account. Currently, there is no public exploit code (Metasploit, Nuclei, ExploitDB), it is not listed in the KEV catalog, and shows no community discussion or media coverage, indicating low active exploitation or public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3CPE matchmatch criteria | cpe:2.3:a:ofono_project:ofono:2.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.