Skip to main content
CISA Known Exploited Vulnerabilities

Qualcomm Multiple Chipsets Use-After-Free Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2024-10-08
Remediation due
2024-10-29

Required action
Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CISA notes
https://git.codelinaro.org/clo/la/platform/vendor/qcom/opensource/dsp-kernel/-/commit/0e27b6c7d2bd8d0453e4465ac2ca49a8f8c440e2 ; https://nvd.nist.gov/vuln/detail/CVE-2024-43047

Description

Memory corruption while maintaining memory maps of HLOS memory.

Severity

CVSS 3.1 · CNA7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
SSVC · CISA-ADP
Exploitationactive
Automatableno
Technical impacttotal

Affected Products

VendorProductAffected versions
Qualcomm, Inc.Snapdragon
FastConnect 6700
FastConnect 6800
FastConnect 6900
FastConnect 7800
QAM8295P
QCA6174A
QCA6391
QCA6426
QCA6436
QCA6574AU
QCA6584AU
QCA6595
QCA6595AU
QCA6688AQ
QCA6696
QCA6698AQ
QCS410
QCS610
QCS6490
Qualcomm Video Collaboration VC1 Platform
Qualcomm Video Collaboration VC3 Platform
SA4150P
SA4155P
SA6145P
SA6150P
SA6155P
SA8145P
SA8150P
SA8155P
SA8195P
SA8295P
SD660
SD865 5G
SG4150P
Snapdragon 660 Mobile Platform
Snapdragon 680 4G Mobile Platform
Snapdragon 685 4G Mobile Platform (SM6225-AD)
Snapdragon 8 Gen 1 Mobile Platform
Snapdragon 865 5G Mobile Platform
Snapdragon 865+ 5G Mobile Platform (SM8250-AB)
Snapdragon 870 5G Mobile Platform (SM8250-AC)
Snapdragon 888 5G Mobile Platform
Snapdragon 888+ 5G Mobile Platform (SM8350-AC)
Snapdragon Auto 5G Modem-RF
Snapdragon Auto 5G Modem-RF Gen 2
Snapdragon X55 5G Modem-RF System
Snapdragon XR2 5G Platform
SW5100
SW5100P
SXR2130
WCD9335
WCD9341
WCD9370
WCD9375
WCD9380
WCD9385
WCN3950
WCN3980
WCN3988
WCN3990
WSA8810
WSA8815
WSA8830
WSA8835

References

1 Links

Record Details

Published
2024-10-07
Last updated
2025-10-21
Assigner (CNA)
qualcomm
Credited to
-

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.