CVE-2024-47249
CVE-2024-47249 is a medium-severity vulnerability in Apache Nimble with a CVSS 3.x base score of 5.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-129.
Key facts
- Severity: Medium (CVSS 3.x base score 5.0)
- EPSS exploit prediction: 1% (46th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2024-42789
- Weakness: CWE-129
- Affected product: Apache Nimble
- Published:
- Last modified:
Description
Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from controller could result in out-of-bound memory corruption and crash. This issue requires broken or bogus Bluetooth controller and thus severity is considered low. This issue affects Apache NimBLE: through 1.7.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.
Frequently asked questions
- What is CVE-2024-47249?
- Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from controller could result in out-of-bound memory corruption and crash. This issue requires broken or bogus Bluetooth controller and thus severity is considered low. This issue affects Apache NimBLE: through 1.7.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.
- How severe is CVE-2024-47249?
- CVE-2024-47249 has a CVSS 3.x base score of 5.0, rated medium severity. It is exploitable over an adjacent network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2024-47249 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (46th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2024-47249?
- CVE-2024-47249 affects Apache Nimble. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2024-47249?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2024-47249 have an EU (EUVD) identifier?
- Yes. CVE-2024-47249 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2024-42789.
- When was CVE-2024-47249 published?
- CVE-2024-47249 was published on 2024-11-26 and last updated on 2026-06-17.
References
- https://github.com/apache/mynewt-nimble/commit/f39330866a85fa4de49246e9d21334bc8d14f0a1
- https://lists.apache.org/thread/7ckxw6481dp68ons627pjcb27c75n0mq
- http://www.openwall.com/lists/oss-security/2024/11/26/3
Affected products (1)
- cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:*
More vulnerabilities in Apache Nimble
- CVE-2026-45813 — High (CVSS 8.8): Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper…
- CVE-2025-62235 — High (CVSS 8.1): Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could…
- CVE-2026-45816 — High (CVSS 7.5): NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled…
- CVE-2026-45815 — High (CVSS 7.5): Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response…
- CVE-2026-45811 — High (CVSS 7.5): Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket…
- CVE-2025-53477 — High (CVSS 7.5): NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command…
All CVEs affecting Apache Nimble →
Other CWE-129 (Improper Validation of Array Index) vulnerabilities
- CVE-2020-27485 — Critical (CVSS 9.9): Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector…
- CVE-2020-27483 — Critical (CVSS 9.9): Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector…
- CVE-2026-21413 — Critical (CVSS 9.8): A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545…
- CVE-2025-27034 — Critical (CVSS 9.8): Memory corruption while selecting the PLMN from SOR failed list.
- CVE-2023-53192 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix nexthop hash size The nexthop code…
- CVE-2025-3357 — Critical (CVSS 9.8): IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code…
Browse all CWE-129 (Improper Validation of Array Index) vulnerabilities →