Home / Vulnerabilities / CVE-2024-43047
HIGH SEVERITY
CVE-2024-43047 Qualcomm · Multiple Chipsets

Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Technical Severity

CVSS v3.1 Metrics

HIGH
7.8 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation Likelihood

EPSS Prediction

1.75 %
Predictive Probability
Percentile Rank
82.2 th

Documented as more likely to be exploited than 82.2% of known CVEs.

Detection Date

Oct 08, 2024

Remediation Due

Oct 29, 2024

CISA Catalog Active

Threat Analysis

Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory.

Remediation Directive

Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

External Intelligence