Apache NimBLE是美国阿帕奇(Apache)基金会的一个开源蓝牙 5.4 堆栈(主机和控制器),完全取代 Nordic 芯片组上的专有 SoftDevice。它是Apache Mynewt 项目的一部分。 Apache NimBLE 1.7.0及之前版本存在安全漏洞,该漏洞源于缓冲区复制未检查输入大小,使用非默认构建配置时,特制的MESH消息可能会导致内存损坏。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache NimBLE | 0 ~ 1.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-47249 | Apache NimBLE: Lack of input sanitization leading to out-of-bound reads in multiple advert | |
| CVE-2024-47250 | Apache NimBLE: Lack of input validation in HCI advertising report could lead to potential | |
| CVE-2024-51569 | Apache NimBLE: Lack of input sanitization leading to out-of-bound reads in Number of Compl |
No comments yet