CVE-2024-51569

CWE-125Out-of-bounds Read3 documents3 sources
Severity
7.5HIGH
EPSS
0.1%
top 64.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 26

Description

Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and invalid read from HCI transport memory. This issue requires broken or bogus Bluetooth controller and thus severity is considered low. This issue affects Apache NimBLE: through 1.7.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-966f-2c6j-qj89: Out-of-bounds Read vulnerability in Apache NimBLE2024-11-26
CVEList
Apache NimBLE: Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler2024-11-26