CVE-2025-62235: Nimble Auth Bypass Spoofing

Authentication bypass vulnerability (CVE-2025-62235) in Apache NimBLE. The stack queries the security database for existing peer keys only if the incoming Security Request contains the BLE_SM_PAIR_AUTHREQ_BOND flag. An attacker can clear this flag to ignore the previously established bond and incorrectly initiate a new unauthenticated pairing procedure inste

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0C
greprules fetch cve-2025-62235-nimble-auth-bypass-spoofing --engine opengrep

Description

Authentication bypass vulnerability (CVE-2025-62235) in Apache NimBLE. The stack queries the security database for existing peer keys only if the incoming Security Request contains the BLE_SM_PAIR_AUTHREQ_BOND flag. An attacker can clear this flag to ignore the previously established bond and incorrectly initiate a new unauthenticated pairing procedure inste