CVE-2024-7540
NixOS vulnerability analysis and mitigation

Overview

The CVE-2024-7540 is an information disclosure vulnerability in oFono, affecting the AT CMGL Command functionality. The vulnerability was discovered and reported by Synacktiv, and was publicly disclosed on August 5, 2024. The vulnerability affects oFono version 1.34 and potentially other versions (NVD, ZDI Advisory).

Technical details

The vulnerability stems from an uninitialized variable issue within the parsing of responses from AT+CMGL commands. The specific flaw exists due to the lack of proper initialization of memory prior to accessing it. The vulnerability has been assigned a CVSS v3.1 base score of 3.3 (Low) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N, indicating local access is required with low attack complexity (ZDI Advisory).

Impact

When successfully exploited, this vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. The impact is limited to information disclosure, with no direct impact on integrity or availability of the system (ZDI Advisory).

Exploitability

To exploit this vulnerability, an attacker must first obtain the ability to execute code on the target modem. The vulnerability can be leveraged in conjunction with other vulnerabilities to potentially execute arbitrary code in the context of root (ZDI Advisory).

Mitigation and workarounds

As of August 5, 2024, there was no official fix available from the vendor. Multiple attempts were made to report the vulnerability to the vendor via the oFono distribution list, Red Hat, and upstream Linux Kernel, but the vendor did not respond. The Linux Kernel team indicated that since it "has nothing to do with the Linux Kernel," it should be reported to the distribution list (ZDI Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18713HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18669HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18235HIGH8.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-17420MEDIUM6.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18250MEDIUM5
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management