
Cloud Vulnerability DB
A community-led vulnerabilities database
The CVE-2024-7540 is an information disclosure vulnerability in oFono, affecting the AT CMGL Command functionality. The vulnerability was discovered and reported by Synacktiv, and was publicly disclosed on August 5, 2024. The vulnerability affects oFono version 1.34 and potentially other versions (NVD, ZDI Advisory).
The vulnerability stems from an uninitialized variable issue within the parsing of responses from AT+CMGL commands. The specific flaw exists due to the lack of proper initialization of memory prior to accessing it. The vulnerability has been assigned a CVSS v3.1 base score of 3.3 (Low) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N, indicating local access is required with low attack complexity (ZDI Advisory).
When successfully exploited, this vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. The impact is limited to information disclosure, with no direct impact on integrity or availability of the system (ZDI Advisory).
To exploit this vulnerability, an attacker must first obtain the ability to execute code on the target modem. The vulnerability can be leveraged in conjunction with other vulnerabilities to potentially execute arbitrary code in the context of root (ZDI Advisory).
As of August 5, 2024, there was no official fix available from the vendor. Multiple attempts were made to report the vulnerability to the vendor via the oFono distribution list, Red Hat, and upstream Linux Kernel, but the vendor did not respond. The Linux Kernel team indicated that since it "has nothing to do with the Linux Kernel," it should be reported to the distribution list (ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."