SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-43061

Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.

HIGH 7.8EPSS 0.11%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.11% probability · 2th percentile
CISA KEV
Not listed
Weakness
CWE-416
Affected
qualcomm/fastconnect 6900 firmware · qualcomm/fastconnect 7800 firmware · qualcomm/qam8295p firmware · qualcomm/qca6574au firmware · qualcomm/qca6696 firmware · qualcomm/qca9367 firmware · qualcomm/qca9377 firmware · qualcomm/qcs8550 firmware · qualcomm/sa6145p firmware · qualcomm/sa6150p firmware · qualcomm/sa6155p firmware · qualcomm/sa8145p firmware · qualcomm/sa8150p firmware · qualcomm/sa8155p firmware · qualcomm/sa8195p firmware · qualcomm/sa8295p firmware · qualcomm/sa8530p firmware · qualcomm/sa8540p firmware · qualcomm/sa9000p firmware · qualcomm/sdm429w firmware · +10 more
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.