Impact
The vulnerability is a reachable assertion in the ATT Read Multiple Variable Response handler of Apache NimBLE. A specially crafted BLE ATT Read Multiple Variable Response packet can trigger the assert in the parser, causing the device to terminate unexpectedly. This loss of service could disrupt operation of the device but does not grant code execution or unauthorized access.
Affected Systems
The affected product is the Apache NimBLE Bluetooth stack maintained by the Apache Software Foundation. Versions up to and including 1.9.0 contain the flaw. The fix is implemented in version 1.10.0, which should be applied to all deployments using the vulnerable releases.
Risk and Exploitability
The CVSS base score of 7.5 indicates a medium severity, while the EPSS score of less than 1 % suggests a low likelihood of exploitation at this time. The flaw is not listed in CISA’s KEV catalog. The attacker would need to send a specially crafted ATT Read Multiple Variable Response packet from a Bluetooth client; the attack vector is thus inferred to be a local or near‑range wireless operation, requiring a nearby Bluetooth‑enabled device to trigger the assertion. No privileged access or code execution is required, but the crash could lead to denial of service. The fix does not affect other functionality.
OpenCVE Enrichment