CVE-2024-24746

HIGH

Apache NimBLE <= 1.6.0 - Denial of Service via GATT Operation

Title source: llm
STIX 2.1

Description

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.  Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: through 1.6.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.

Scores

CVSS v3 7.5
EPSS 0.0146
EPSS Percentile 70.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-835
Status published
Products (1)
apache/nimble < 1.7.0
Published Apr 06, 2024
Tracked Since Feb 18, 2026