Description
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
Published: 2026-09-02
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE refers to a buffer overflow flaw within the Gammu SMS Daemon component of Drupal, as indicated by CWE-119. The description does not disclose specific details about how the overflow is triggered, but a buffer overflow can lead to memory corruption, potentially allowing an attacker to influence program execution. Exact consequences are unclear because no exploitation details are provided; the advisory classifies the issue as critical. The payload, if crafted legitimately, could corrupt the daemon’s memory but it is uncertain whether this culminates in arbitrary code execution or other system compromise.

Affected Systems

The impacted product is the Drupal Gammu SMS Daemon. All releases of the daemon are listed as vulnerable, and no specific version constraints are provided, so any deployed instance should be treated as affected.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so exploitation likelihood is not quantified. The CVSS score of 5.9 indicates medium severity. Based on the description, it is inferred that the daemon listens on a network interface and could be reached by external SMS traffic, so a remote exploitation path is possible but the precise attack vector is unconfirmed. Given the product is unsupported and classified as critical, the overall risk remains high until a patch is applied.

Generated by OpenCVE AI on September 3, 2026 at 12:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for any available patch or upgrade for the Gammu SMS Daemon from the Drupal security advisories site and apply it immediately if one exists.
  • If no fix is available, restrict the daemon’s network exposure by allowing inbound connections only from trusted IP addresses or disabling the service entirely until a replacement is deployed.
  • Implement traffic monitoring and anomaly detection on the network interface used by the daemon to identify potential exploitation attempts during the interim.

Generated by OpenCVE AI on September 3, 2026 at 12:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 03 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal gammu Sms Daemon
Vendors & Products Drupal
Drupal gammu Sms Daemon

Wed, 02 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
Title Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100
References

Subscriptions

Drupal Gammu Sms Daemon
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-02T18:42:08.326Z

Reserved: 2026-08-19T16:36:05.908Z

Link: CVE-2026-76757

cve-icon Vulnrichment

Updated: 2026-09-02T18:40:28.974Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T13:18:10.977

Modified: 2026-09-02T19:18:04.053

Link: CVE-2026-76757

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T12:15:03Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer