CVE-2023-46870

HIGH

Nordic Semiconductor nRF Sniffer for Bluetooth LE <4.1.1 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-46870. PoCs published by Chapoly1305.

AI-analyzed exploit summary The repository provides a detailed technical analysis of CVE-2023-46870, a privilege escalation vulnerability in Nordic Semiconductor nRF Sniffer for Bluetooth LE due to incorrect file permissions (777/666) on critical scripts. It includes replication steps, mitigation advice, and references to external resources like YouTube videos for further context.

Description

extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1 have set incorrect file permission, which allows attackers to do code execution via modified bash and python scripts.

Exploits (1)

nomisec WRITEUP
by Chapoly1305 · poc
https://github.com/Chapoly1305/CVE-2023-46870

The repository provides a detailed technical analysis of CVE-2023-46870, a privilege escalation vulnerability in Nordic Semiconductor nRF Sniffer for Bluetooth LE due to incorrect file permissions (777/666) on critical scripts. It includes replication steps, mitigation advice, and references to external resources like YouTube videos for further context.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Nordic Semiconductor nRF Sniffer for Bluetooth LE versions 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1
No auth needed
Prerequisites: Access to the system where the vulnerable nRF Sniffer for Bluetooth LE is installed · Ability to modify files in the Wireshark extcap directory
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 7.3
EPSS 0.0036
EPSS Percentile 28.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Published May 14, 2024
Tracked Since Feb 18, 2026