CVE-2024-24746

CWE-8353 documents3 sources
Severity
7.5HIGH
EPSS
0.1%
top 68.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 6

Description

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE. Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: through 1.6.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
CVEList
Apache NimBLE: Denial of service in NimBLE Bluetooth stack2024-04-06
GHSA
GHSA-wpv3-6qr5-9rmx: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE2024-04-06