https://seclists.org/oss-sec/2024/q4/121: CVE-2024-47250: Apache NimBLE: Lack of input validation in HCI advertising port could lead to potential out-of-bound access
Published Nov 26, 2024
·Updated
Affected Software
1 affected component
Apache NimBLE<=1.7.0
Frequently Asked Questions
1
What is the severity of CVE-2024-47250?
The severity of CVE-2024-47250 is classified as low.
2
Which versions of Apache NimBLE are affected by CVE-2024-47250?
Apache NimBLE versions up to and including 1.7.0 are affected by CVE-2024-47250.
3
What is the main exploit associated with CVE-2024-47250?
CVE-2024-47250 involves an out-of-bounds read vulnerability due to lack of input validation in the HCI advertising port.
4
How do I fix CVE-2024-47250?
To mitigate CVE-2024-47250, upgrade to a version of Apache NimBLE that addresses this vulnerability.
5
What could be the consequence of exploiting CVE-2024-47250?
Exploitation of CVE-2024-47250 could lead to out-of-bound access and the generation of bogus GAP 'device found' events.