CVE-2025-62235: Apache Mynewt NimBLE: Incorrect handling of SMP Security Request could lead to undesirable pairing
Authentication Bypass by Spoofing vulnerability in Apache NimBLE.
Receiving specially crafted Security Request could lead to removal of original bond and re-bond with impostor. This issue affects Apache NimBLE: through 1.8.0.
Users are recommended to upgrade to version 1.9.0, which fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62235?
CVE-2025-62235 is classified as a high severity vulnerability due to the potential for authentication bypass.
How do I fix CVE-2025-62235?
To address CVE-2025-62235, users should upgrade Apache NimBLE to version 1.9.0 or later.
What does CVE-2025-62235 affect?
CVE-2025-62235 affects Apache NimBLE versions up to and including 1.8.0.
What is the nature of the vulnerability in CVE-2025-62235?
CVE-2025-62235 is an authentication bypass vulnerability that can be exploited through specially crafted Security Requests.
Can an attacker exploit CVE-2025-62235 remotely?
Yes, an attacker can potentially exploit CVE-2025-62235 remotely to impersonate a legitimate bonded device.