{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-47250","assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","state":"PUBLISHED","assignerShortName":"apache","dateReserved":"2024-09-23T09:14:40.561Z","datePublished":"2024-11-26T11:17:19.568Z","dateUpdated":"2024-12-06T10:16:02.631Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Apache NimBLE","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"1.7.0","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"reporter","value":"Eunkyu Lee"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Out-of-bounds Read vulnerability in Apache NimBLE.</p><span style=\"background-color: rgb(255, 255, 255);\">Missing proper validation of HCI advertising report could lead to out-of-bound access when parsing HCI event and thus bogus G</span>AP 'device found' events being sent.<br>This issue requires broken or bogus Bluetooth controller and thus severity is considered low.<br><p>This issue affects Apache NimBLE: through 1.7.0.<br></p><p>Users are recommended to upgrade to version 1.8.0, which fixes the issue.</p>"}],"value":"Out-of-bounds Read vulnerability in Apache NimBLE.\n\nMissing proper validation of HCI advertising report could lead to out-of-bound access when parsing HCI event and thus bogus GAP 'device found' events being sent.\nThis issue requires broken or bogus Bluetooth controller and thus severity is considered low.\nThis issue affects Apache NimBLE: through 1.7.0.\n\n\nUsers are recommended to upgrade to version 1.8.0, which fixes the issue."}],"metrics":[{"other":{"content":{"text":"low"},"type":"Textual description of severity"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-125","description":"CWE-125 Out-of-bounds Read","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache","dateUpdated":"2024-12-06T10:16:02.631Z"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/zdb50spojlqbn0yxd866mbzqjt2vpt85"},{"tags":["patch"],"url":"https://github.com/apache/mynewt-nimble/commit/3b7a32ea09a3bffaab831ee0ab193a2375fc4df6"},{"tags":["patch"],"url":"https://github.com/apache/mynewt-nimble/commit/23d61150ddae4bc8356356d7ef09d816fb89da45"}],"source":{"discovery":"UNKNOWN"},"title":"Apache NimBLE: Lack of input validation in HCI advertising report could lead to potential out-of-bound access","x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"title":"CVE Program Container","references":[{"url":"http://www.openwall.com/lists/oss-security/2024/11/26/4"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-11-26T13:09:22.969Z"}},{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":5,"attackVector":"ADJACENT_NETWORK","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","integrityImpact":"LOW","userInteraction":"NONE","attackComplexity":"HIGH","availabilityImpact":"LOW","privilegesRequired":"NONE","confidentialityImpact":"LOW"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-11-26T16:35:20.978314Z","id":"CVE-2024-47250","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-11-26T16:36:02.269Z"}}]}}