Vulnerability record · CVE-2024-43047 · published 7 October 2024
CVE-2024-43047: Qualcomm chipset firmware use-after-free in HLOS memory map handling
Qualcomm · Fastconnect 6700 Firmware
A use-after-free (CWE-416) in Qualcomm chipset firmware occurs while maintaining memory maps of HLOS memory, leading to memory corruption. It affects a broad set of FastConnect, QCA, QCS and video collaboration platform firmware products. Because it is listed in CISA KEV, it is treated as exploited in the wild.
Description
Memory corruption while maintaining memory maps of HLOS memory.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a high-severity memory corruption flaw with confirmed exploitation per CISA KEV, though it requires local access and low privileges.
What it is
A use-after-free (CWE-416) in Qualcomm chipset firmware occurs while maintaining memory maps of HLOS memory, leading to memory corruption. It affects a broad set of FastConnect, QCA, QCS and video collaboration platform firmware products. Because it is listed in CISA KEV, it is treated as exploited in the wild.
Impact
An attacker who can trigger the flaw gains high impact to confidentiality, integrity and availability, potentially achieving code execution or memory corruption within the affected firmware context.
Attack surface
The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the attacker needs local access to the device or a position that can reach the affected firmware interface. No remote vector is described in the record.
Exploitation
CVE-2024-43047 was added to CISA KEV on 2024-10-08, indicating known exploitation, while EPSS is low at roughly 0.67 percent (50th percentile). No ransomware campaign use is documented.
What to do
- Apply the Qualcomm October 2024 security bulletin patches for all listed FastConnect, QCA, QCS and video collaboration platform firmware.
- If patching is not possible, follow vendor mitigations or discontinue use of affected products per CISA KEV guidance.
- Restrict local access and privilege escalation paths on devices using the affected chipsets.
- Track the CISA KEV remediation due date of 2024-10-29 and verify completion.
- Inventory devices and modules containing the listed Qualcomm firmware to confirm coverage.
Detection
- Monitor for crashes or abnormal memory corruption events in firmware or kernel logs on affected Qualcomm-based devices.
- Hunt for local privilege escalation attempts or unusual processes interacting with chipset firmware interfaces.
- Correlate device telemetry with known exploitation indicators for CVE-2024-43047 from vendor and CISA advisories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-43047 to the Known Exploited Vulnerabilities catalog on 8 October 2024 as "Qualcomm Multiple Chipsets Use-After-Free Vulnerability". Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Federal deadline 29 October 2024.
Affected products
64 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-43047 | US Government Resource |
Track CVE-2024-43047 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-43047), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.