PT-2025-27606 · Nokia · Nokia Single Ran Baseband Oam Service

Guillaume Teissier

+3

·

Published

2025-07-02

·

Updated

2025-07-02

·

CVE-2025-24328

CVSS v2.0

4.3

Medium

VectorAV:A/AC:H/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Nokia Single RAN baseband OAM service component versions prior to 24R1-SR 1.0 MP
Description: The issue occurs when a crafted SOAP "set" operation message is sent within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network, causing the Nokia Single RAN baseband OAM service component to restart. The OAM service component restarts automatically after the stack overflow without causing a base station restart or network service degradation, and without leaving any permanent impact on the Nokia Single RAN baseband OAM service.
Recommendations: For versions prior to 24R1-SR 1.0 MP, update to release 24R1-SR 1.0 MP or later to resolve the issue. As a temporary workaround, consider restricting access to the SOAP "set" operation message within the MNO internal RAN management network to minimize the risk of exploitation.

Fix

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-07971
CVE-2025-24328

Affected Products

Nokia Single Ran Baseband Oam Service