Impact
Improper input validation in the Mesh Proxy SAR reassembly of Apache NimBLE allows attackers to supply malformed reassembly data. The failure to validate input size and format can lead to excessive memory usage and unstable parsing behavior, potentially causing application crashes or denial of service. This weakness is a classic example of CWE‑20: Improper Input Validation.
Affected Systems
Apache NimBLE, distributed by the Apache Software Foundation, is affected in all released versions up to and including 1.9.0. Users running any version in the 1.9.0 series or earlier are vulnerable; newer releases such as 1.10.0 contain the fix.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1% suggests low current exploitation activity, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is through the mesh network: an attacker who can inject crafted SAR packets into the proxy is inferred as the necessary condition for exploitation. If such access is achieved, the vulnerability could reliably induce a crash, leading to a denial‑of‑service scenario.
OpenCVE Enrichment