Description
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
Published: 2026-09-02
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is described as critical and applies to all versions of the Gammu SMS Daemon. The official description does not specify the flaw type or its impact beyond indicating that all releases are affected. Therefore, the exact capabilities an attacker might gain are unknown from the provided data.

Affected Systems

Vendor Drupal, product Gammu SMS Daemon. All released versions are impacted, as indicated by the description showing *.* in the affected‑versions list. No specific version numbers or patch information are supplied, implying the issue applies uniformly to all current builds of the daemon.

Risk and Exploitability

The CVSS score of 5.9 indicates medium severity, the EPSS score is unavailable, and the vulnerability is not listed in CISA KEV. The title labels the flaw as critical, but the CVSS score indicates medium severity, so the critical designation is not fully supported by the available metrics. Attack vector details are absent, so it is unclear how an adversary would trigger the flaw. The unsupported status implied by the title may increase the risk, as no vendor patch or ongoing support is anticipated.

Generated by OpenCVE AI on September 3, 2026 at 11:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or uninstall the Gammu SMS Daemon if it is not essential to operations.
  • Restrict access to the daemon by firewalling or VLAN segmentation, allowing only trusted hosts to communicate with the service.
  • Implement logging and traffic monitoring to detect anomalous commands or patterns, and investigate any suspicious activity promptly.

Generated by OpenCVE AI on September 3, 2026 at 11:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 03 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal gammu Sms Daemon
Vendors & Products Drupal
Drupal gammu Sms Daemon

Wed, 02 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
Title Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100
References

Subscriptions

Drupal Gammu Sms Daemon
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-02T18:41:48.170Z

Reserved: 2026-08-19T16:36:05.908Z

Link: CVE-2026-76756

cve-icon Vulnrichment

Updated: 2026-09-02T18:41:38.854Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T13:18:10.883

Modified: 2026-09-02T19:18:03.893

Link: CVE-2026-76756

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T11:45:03Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer