CVE-2024-7539

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Aug 6, 2024
Updated: Aug 29, 2024
CWE ID 787
CWE ID 121

Summary

CVE-2024-7539 is a stack-based buffer overflow vulnerability in oFono's CUSD module. This issue allows local attackers to execute arbitrary code on affected installations of oFono, provided they have the ability to execute code on the target modem. The flaw stems from insufficient validation of user-supplied data lengths during the parsing of responses from AT+CUSD commands, resulting in a buffer overflow that enables code execution with root privileges. (ZDI-CAN-23195 first disclosed this vulnerability.)

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share