Nimble
Vendor:
First CVE: Apr 6, 2024 · Active for 2 years
9
Total CVEs
More Total CVEs than 86% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nimble over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 6, 2024
2 years ago
Most Recent CVE
Jan 10, 2026
195 days ago
CVE Severity & Scoring
Nimble9 CVEs
11%
33%
56%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network4 (44.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network5 (55.6%)
Attack Complexity
Low6 (66.7%)
High3 (33.3%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-62235HIGH Authentication Bypass by Spoofing vulnerability in Apache NimBLE.
Receiving specially crafted Security Request could lead to removal of original bond and re-bond with impostor.
Th | Jan 10, 2026 | 8.1 | 27 | NO | NO |
CVE-2025-53477HIGH NULL Pointer Dereference vulnerability in Apache Nimble.
Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL pointer dereference.
This issue | Jan 10, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-52435HIGH J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE.
Improper handling of Pause Encryption procedure on Link Layer results in a previously e | Jan 10, 2026 | 7.5 | 24 | NO | NO |
CVE-2024-51569HIGH Out-of-bounds Read vulnerability in Apache NimBLE.
Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and invali | Nov 26, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-24746HIGH Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.
Specially crafted GATT operation can cause infinite loop in GATT server leading to denial o | Apr 6, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-47248MEDIUM Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE.
Specially crafted MESH message could result in memory corruption when non-de | Nov 26, 2024 | 6.3 | 19 | NO | NO |
CVE-2024-47250MEDIUM Out-of-bounds Read vulnerability in Apache NimBLE.
Missing proper validation of HCI advertising report could lead to out-of-bound access when parsing HCI event and thus bogus GAP | Nov 26, 2024 | 5.0 | 17 | NO | NO |
CVE-2024-47249MEDIUM Improper Validation of Array Index vulnerability in Apache NimBLE.
Lack of input validation for HCI events from controller could result in out-of-bound memory corruption and crash | Nov 26, 2024 | 5.0 | 17 | NO | NO |
Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memory read in H4 driver.
This issue affects Apache NimBLE: thr | Jan 10, 2026 | 3.1 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Nimble
Top CWEs
Versions
No cataloged versions.