Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-47250

17
FAUCET Score

CVE-2024-47250 is an out-of-bounds read vulnerability in Apache NimBLE, affecting versions up to 1.7.0. This flaw, stemming from improper validation of HCI advertising reports, could lead to out-of-bounds access during HCI event parsing and result in erroneous GAP 'device found' events. Rated Medium (CVSS 5.0), its exploitation requires a broken or bogus Bluetooth controller, making the attack complexity high and the potential impact low for confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.8.0CPE matchmatch criteria
cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.0MEDIUM

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
1.6
Impact Score
3.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.66%
Probability of exploitation in next 30 days
EPSS Percentile
48.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0066 is in the 93rd percentile among its peer group of 1,749 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

openwall.com / lists/oss-security/2024/11/26/4
Mailing ListVendor Advisory
github.com / apache/mynewt-nimble/commit/23d61150ddae4bc8356356d7ef09d816fb89da45
Patch
github.com / apache/mynewt-nimble/commit/3b7a32ea09a3bffaab831ee0ab193a2375fc4df6
Patch
lists.apache.org / thread/zdb50spojlqbn0yxd866mbzqjt2vpt85
Mailing ListVendor Advisory