CVE-2025-52435: Apache Mynewt NimBLE: Invalid error handling in pause encryption procedure in NimBLE controller
J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE.
Improper handling of Pause Encryption procedure on Link Layer results in a previously encrypted connection being left in un-encrypted state allowing an eavesdropper to observe the remainder of the exchange. This issue affects Apache NimBLE: through <= 1.8.0.
Users are recommended to upgrade to version 1.9.0, which fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52435?
CVE-2025-52435 is classified as a medium-severity vulnerability due to potential data exposure risks.
How do I fix CVE-2025-52435?
To mitigate CVE-2025-52435, upgrade Apache NimBLE to version 1.9.0 or later, where the encryption handling issue has been addressed.
Who is affected by CVE-2025-52435?
CVE-2025-52435 affects users of Apache NimBLE versions up to and including 1.8.0.
What type of vulnerability is CVE-2025-52435?
CVE-2025-52435 is a data transmission vulnerability due to improper handling of encryption procedures.
Can CVE-2025-52435 be exploited remotely?
Yes, CVE-2025-52435 can be exploited remotely, allowing eavesdroppers to observe unencrypted data transmissions.