cbcvebase.
CVE-2024-47250
published 2024-11-26

CVE-2024-47250: Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to out-of-bound access when parsing HCI event…

PriorityP424medium5CVSS 3.1
AVAACHPRNUINSUCLILAL
EPSS
0.66%
47.6th percentile
Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to out-of-bound access when parsing HCI event and thus bogus GAP 'device found' events being sent. This issue requires broken or bogus Bluetooth controller and thus severity is considered low. This issue affects Apache NimBLE: through 1.7.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.

Affected

2 ranges
VendorProductVersion rangeFixed in
apachenimble< 1.8.01.8.0
apache_software_foundationapache_nimble<= 1.7.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.