Impact
The CVE refers to a buffer overflow flaw within the Gammu SMS Daemon component of Drupal, as indicated by CWE-119. The description does not disclose specific details about how the overflow is triggered, but a buffer overflow can lead to memory corruption, potentially allowing an attacker to influence program execution. Exact consequences are unclear because no exploitation details are provided; the advisory classifies the issue as critical. The payload, if crafted legitimately, could corrupt the daemon’s memory but it is uncertain whether this culminates in arbitrary code execution or other system compromise.
Affected Systems
The impacted product is the Drupal Gammu SMS Daemon. All releases of the daemon are listed as vulnerable, and no specific version constraints are provided, so any deployed instance should be treated as affected.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so exploitation likelihood is not quantified. The CVSS score of 5.9 indicates medium severity. Based on the description, it is inferred that the daemon listens on a network interface and could be reached by external SMS traffic, so a remote exploitation path is possible but the precise attack vector is unconfirmed. Given the product is unsupported and classified as critical, the overall risk remains high until a patch is applied.
OpenCVE Enrichment