PT-2025-27606 · Nokia · Nokia Single Ran Baseband Oam Service
Guillaume Teissier
+3
·
Published
2025-07-02
·
Updated
2025-07-02
·
CVE-2025-24328
CVSS v2.0
4.3
Medium
| Vector | AV:A/AC:H/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Nokia Single RAN baseband OAM service component versions prior to 24R1-SR 1.0 MP
Description:
The issue occurs when a crafted SOAP "set" operation message is sent within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network, causing the Nokia Single RAN baseband OAM service component to restart. The OAM service component restarts automatically after the stack overflow without causing a base station restart or network service degradation, and without leaving any permanent impact on the Nokia Single RAN baseband OAM service.
Recommendations:
For versions prior to 24R1-SR 1.0 MP, update to release 24R1-SR 1.0 MP or later to resolve the issue. As a temporary workaround, consider restricting access to the SOAP "set" operation message within the MNO internal RAN management network to minimize the risk of exploitation.
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nokia Single Ran Baseband Oam Service