7.8

CVE-2024-43060

Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.

Data is provided by the National Vulnerability Database (NVD)
QualcommAr8035 Firmware Version-
   QualcommAr8035
QualcommQam8295p Firmware Version-
   QualcommQam8295p
QualcommQca6696 Firmware Version-
   QualcommQca6696
QualcommQca8081 Firmware Version-
   QualcommQca8081
QualcommQca8337 Firmware Version-
   QualcommQca8337
QualcommQca9367 Firmware Version-
   QualcommQca9367
QualcommQca9377 Firmware Version-
   QualcommQca9377
QualcommQcc710 Firmware Version-
   QualcommQcc710
QualcommQcn6224 Firmware Version-
   QualcommQcn6224
QualcommQcn6274 Firmware Version-
   QualcommQcn6274
QualcommQcs8550 Firmware Version-
   QualcommQcs8550
QualcommQfw7114 Firmware Version-
   QualcommQfw7114
QualcommQfw7124 Firmware Version-
   QualcommQfw7124
QualcommSa6145p Firmware Version-
   QualcommSa6145p
QualcommSa6150p Firmware Version-
   QualcommSa6150p
QualcommSa6155p Firmware Version-
   QualcommSa6155p
QualcommSa8145p Firmware Version-
   QualcommSa8145p
QualcommSa8150p Firmware Version-
   QualcommSa8150p
QualcommSa8155p Firmware Version-
   QualcommSa8155p
QualcommSa8195p Firmware Version-
   QualcommSa8195p
QualcommSa8295p Firmware Version-
   QualcommSa8295p
QualcommSa8530p Firmware Version-
   QualcommSa8530p
QualcommSa8540p Firmware Version-
   QualcommSa8540p
QualcommSa9000p Firmware Version-
   QualcommSa9000p
QualcommSdm429w Firmware Version-
   QualcommSdm429w
QualcommSxr2230p Firmware Version-
   QualcommSxr2230p
QualcommSxr2250p Firmware Version-
   QualcommSxr2250p
QualcommWcd9340 Firmware Version-
   QualcommWcd9340
QualcommWcd9380 Firmware Version-
   QualcommWcd9380
QualcommWcd9385 Firmware Version-
   QualcommWcd9385
QualcommWcn3620 Firmware Version-
   QualcommWcn3620
QualcommWcn3660b Firmware Version-
   QualcommWcn3660b
QualcommWsa8830 Firmware Version-
   QualcommWsa8830
QualcommWsa8832 Firmware Version-
   QualcommWsa8832
QualcommWsa8835 Firmware Version-
   QualcommWsa8835
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.061
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
product-security@qualcomm.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

CWE-823 Use of Out-of-range Pointer Offset

The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.