PT-2023-19969 · Nokia · Aashell+1

Geoffrey Bertoli

+1

·

Publicado

2023-06-16

·

Atualizado

2024-12-12

·

CVE-2023-25188

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NOKIA Airscale ASIKA Single RAN devices versions prior to 21B
Description An issue was discovered where if security hardenings are removed from the Nokia Single RAN BTS baseband unit by a CSP as a BTS administrator, the BTS baseband unit diagnostic tool AaShell allows unauthenticated access from the mobile network solution internal BTS management network to the BTS embedded Linux operating-system level. This access is possible because AaShell, which is disabled by default, can be accessed without authentication.
Recommendations For versions prior to 21B, as a temporary workaround, consider disabling the AaShell diagnostic tool until a patch is available. Restrict access to the BTS baseband unit to minimize the risk of exploitation. Ensure that security hardenings are not removed from the Nokia Single RAN BTS baseband unit to prevent unauthenticated access.

Correção

Improper Privilege Management

Origin Validation Error

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-25188

Produtos afetados

Aashell
Nokia Airscale Asika Single Ran