External risk intelligence

Qualcomm Chipsets Memory Corruption Vulnerability.

CVE advisoryKnown Exploit

CVE-2024-43047

Qualcomm chipsets are affected by a memory corruption vulnerability. This could allow unauthorized access and modification of data and systems, posing a business risk by potentially impacting operational integrity.

1Halo Surface Signal

Use After Free

Qualcomm Fastconnect 6700 Firmware

External exposure likelihood

Halo Surface Signal score for CVE-2024-43047

This vulnerability resides within firmware for specific chipsets and SoC components. It requires local access to the device's hardware or internal subsystem memory, making it inherently isolated and not reachable via public-facing network services or common internet-exposed endpoints.

Horizon Alert

Summary of the vulnerability and why it matters

Certain Qualcomm chipsets are affected by a memory corruption vulnerability. This flaw can allow unauthorized actions to occur within the device's memory management. The primary impact could be unauthorized access to or modification of data, potentially affecting system stability and data integrity.

  • Vulnerable Qualcomm chipsets
  • Memory corruption flaw
  • Data compromise and instability

Attack Path

How an attacker could exploit the issue

Qualcomm chipsets are susceptible to memory corruption issues within DSP Services. This vulnerability can arise from improper handling of memory maps associated with HLOS memory. An attacker could exploit this to gain unauthorized control over affected systems.

  • Local access required for exposure.
  • Attacker triggers memory corruption.
  • Results in system control.

Live Threat

Current exploitation, exposure, and threat context

A memory corruption vulnerability exists in certain Qualcomm chipsets, stemming from memory map issues within HLOS memory. This vulnerability could allow for unauthorized modification or access to system memory, potentially impacting the confidentiality, integrity, and availability of data processed by these chipsets. The risk associated with this vulnerability is considered high due to the potential for significant damage if exploited.

  • Likely attacker skill level: Low
  • Required access or conditions: Local access to the device
  • Business risk or urgency: High

Priority actions

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects multiple Qualcomm chipsets due to memory corruption while maintaining memory maps. The potential impact includes unauthorized access and modification of data, as well as denial of service to affected systems. Organizations using these chipsets should take immediate steps to identify and mitigate risks.

  • Find affected assets.
  • Reduce exposure or isolate risk.
  • Fix, verify, and monitor.

Frequently asked questions

What type of vulnerability is CVE-2024-43047 and how does it manifest?

CVE-2024-43047 is a Use After Free vulnerability (CWE-416). It occurs due to memory corruption within DSP Services while maintaining memory maps of HLOS memory on affected Qualcomm chipsets.

Which Qualcomm chipsets are impacted by CVE-2024-43047?

Numerous Qualcomm chipsets are affected, including various FastConnect, QAM, QCA, QCS, SA, SD, SG, and Snapdragon models, as well as Video Collaboration platforms and modem-RF components. The full list is extensive and detailed in vendor advisories.

What is the severity and attack vector for CVE-2024-43047?

This vulnerability is rated as HIGH severity with a base score of 7.8 (CVSS:3.1). The attack vector is Local (AV:L), meaning an attacker needs privileged access to the affected system or device to exploit it.

How does Halo Surface Signal assess the risk of CVE-2024-43047?

Halo Surface Signal classifies the risk as 'Very unlikely' due to the vulnerability residing in firmware and requiring local access to device hardware or internal memory, preventing exploitation via public network services.

What actions should be taken to address CVE-2024-43047?

Qualcomm advises applying remediations or mitigations as per their instructions. If no such solutions are available, discontinuing the use of the affected product is recommended.

References