CVE-2024-24746
HIGHApache NimBLE <= 1.6.0 - Denial of Service via GATT Operation
Title source: llmDescription
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE. Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: through 1.6.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.
References (3)
Core 3
Core References
Mailing List vendor-advisory
https://lists.apache.org/thread/bptkzc0o2ymjk8qqzqdmy39kcmh27078
Scores
CVSS v3
7.5
EPSS
0.0146
EPSS Percentile
70.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-835
Status
published
Products (1)
apache/nimble
< 1.7.0
Published
Apr 06, 2024
Tracked Since
Feb 18, 2026