Impact
Fathom 2.4 contains a classic buffer overflow (CWE-120) in the Authorization Code field. A local attacker can submit a 6000‑byte payload during activation, causing the application to crash and resulting in denial of service. This disrupts service availability for all users until the application is restarted.
Affected Systems
Fathom version 2.4 is affected. No other products or versions are mentioned in the advisory.
Risk and Exploitability
The CVSS score of 6.8 denotes moderate severity, while the EPSS score of < 1 % indicates a very low probability of exploitation in the wild. The vulnerability is not included in CISA’s KEV catalog. Attackers must be local to the machine running Fathom and can trigger the denial of service by submitting a crafted payload via the Authorization Code field. No public exploit has been reported beyond the proof‑of‑concept; the risk is primarily availability disruption rather than privilege escalation or data exposure.
OpenCVE Enrichment