PT-2026-1813 · Apache · Apache Nimble

Published

2026-01-09

·

Updated

2026-01-10

·

CVE-2025-52435

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache NimBLE versions through 1.8.0
Description A configuration issue exists where data transmission occurs without encryption. Specifically, improper handling of the Pause Encryption procedure on the Link Layer can result in a previously encrypted connection reverting to an unencrypted state, potentially allowing an eavesdropper to observe subsequent data exchange.
Recommendations Upgrade to version 1.9.0.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-52435

Affected Products

Apache Nimble