PT-2025-27607 · Nokia · Nokia Single Ran Baseband
Guillaume Teissier
+3
·
Published
2025-07-02
·
Updated
2025-07-02
·
CVE-2025-24329
CVSS v2.0
6.5
Medium
| Vector | AV:A/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Nokia Single RAN baseband software versions prior to 24R1-SR 1.0 MP
Description:
The issue arises when a crafted SOAP "provision" operation message archive field is sent within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network, causing a path traversal issue. This has been mitigated in release 24R1-SR 1.0 MP and later by utilizing libarchive APIs with security options enabled.
Recommendations:
For versions prior to 24R1-SR 1.0 MP, update to release 24R1-SR 1.0 MP or later to resolve the issue.
As a temporary workaround, consider restricting access to the SOAP "provision" operation message archive field within the MNO internal RAN management network until a patch is available.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nokia Single Ran Baseband