Apache NimBLE是美国阿帕奇(Apache)基金会的一个开源蓝牙 5.4 堆栈(主机和控制器),完全取代 Nordic 芯片组上的专有 SoftDevice。它是Apache Mynewt 项目的一部分。 Apache NimBLE 1.7.0版本及之前版本存在安全漏洞,该漏洞源于如果未正确验证 HCI 已完成数据包数,则在解析 HCI 事件时可能会导致越界访问,以及从 HCI 传输内存中读取无效数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache NimBLE | 0 ~ 1.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-47248 | Apache NimBLE: Buffer overflow in NimBLE MESH Bluetooth stack | |
| CVE-2024-47249 | Apache NimBLE: Lack of input sanitization leading to out-of-bound reads in multiple advert | |
| CVE-2024-47250 | Apache NimBLE: Lack of input validation in HCI advertising report could lead to potential |
No comments yet