CVE-2024-7540 is an uninitialized variable vulnerability in oFono, specifically affecting the parsing of AT+CMGL command responses, which can lead to local information disclosure. This vulnerability has a low CVSS score of 3.3, requiring local access and code execution on the target modem to exploit, potentially allowing for root-level arbitrary code execution when chained with other vulnerabilities. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.34CPE matchmatch criteria | cpe:2.3:a:ofono_project:ofono:1.34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.