CVE-2025-52435 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause Encryption procedure on Link Layer resul…
High CVSS: 7.5

CVE-2025-52435

J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE.

Improper handling of Pause Encryption procedure on Link Layer results in a previously encrypted connection being left in un-encrypted state allowing an eavesdropper to observe the remainder of the exchange.
This issue affects Apache NimBLE: through <= 1.8.0.

Users are recommended to upgrade to version 1.9.0, which fixes the issue.
Vendor
Apache
Product
Nimble
CWE
CWE-5
Yayın Tarihi
2026-01-10 10:15:50
Güncelleme
2026-01-14 16:30:55
Source Identifier
security@apache.org
KEV Date Added
-

Kategoriler

Referanslar