PT-2024-12050 · Nokia · Bts

Geoffrey Bertoli

+1

·

Published

2024-09-25

·

Updated

2024-10-29

·

CVE-2023-25189

CVSS v3.1

3.3

Low

VectorAC:H/AV:L/A:N/C:L/I:L/PR:L/S:U/UI:R
Name of the Vulnerable Software and Affected Versions BTS (affected versions not specified)
Description The issue concerns an information disclosure vulnerability. Mobile network operator personnel connected over BTS Web Element Manager can read BTS service operation details performed by Nokia Care service personnel via SSH, regardless of their access privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-25189

Affected Products

Bts