CVE-2024-24746 is a high-severity "Infinite Loop" vulnerability in Apache NimBLE versions through 1.6.0. An unauthenticated attacker can trigger a denial-of-service (DoS) in the Bluetooth stack or device by sending a specially crafted GATT operation to the GATT server. While the CVSS score is 7.5, indicating a significant impact, there is currently no evidence of active exploitation, publicly available exploit code, or community discussion surrounding this vulnerability. Users are strongly advised to upgrade to Apache NimBLE version 1.7.0 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.0CPE matchmatch criteria | cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.