#VU121103 Cleartext transmission of sensitive information in Apache NimBLE - CVE-2025-52435
Published: January 8, 2026
Apache NimBLE
Apache Foundation
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper handling of Pause Encryption procedure on Link Layer, which results in a previously encrypted connection being left in un-encrypted state. A remote attacker with ability to intercept network traffic can gain access to sensitive data.