Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-52435

Опубликовано: 10 янв. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE.

Improper handling of Pause Encryption procedure on Link Layer results in a previously encrypted connection being left in un-encrypted state allowing an eavesdropper to observe the remainder of the exchange. This issue affects Apache NimBLE: through <= 1.8.0.

Users are recommended to upgrade to version 1.9.0, which fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:*
Версия до 1.9.0 (исключая)

EPSS

Процентиль: 9%
0.00032
Низкий

7.5 High

CVSS3

Дефекты

CWE-5

Связанные уязвимости

CVSS3: 7.5
github
28 дней назад

J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause Encryption procedure on Link Layer results in a previously encrypted connection being left in un-encrypted state allowing an eavesdropper to observe the remainder of the exchange. This issue affects Apache NimBLE: through <= 1.8.0. Users are recommended to upgrade to version 1.9.0, which fixes the issue.

EPSS

Процентиль: 9%
0.00032
Низкий

7.5 High

CVSS3

Дефекты

CWE-5