PT-2025-27608 · Nokia · Nokia Single Ran Baseband

Guillaume Teissier

+3

·

Published

2025-07-02

·

Updated

2025-07-02

·

CVE-2025-24330

CVSS v2.0

6.5

Medium

VectorAV:A/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Nokia Single RAN baseband software versions prior to 24R1-SR 1.0 MP
Description: The issue arises when a crafted SOAP "provision" operation message is sent with a malicious PlanId field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network, causing a path traversal issue. This has been mitigated in release 24R1-SR 1.0 MP and later by performing PlanId field input validations in the OAM service software.
Recommendations: For versions prior to 24R1-SR 1.0 MP, update to release 24R1-SR 1.0 MP or later to resolve the issue. As a temporary workaround, consider restricting access to the SOAP "provision" operation message endpoint to minimize the risk of exploitation. Avoid using the PlanId field in the affected API endpoint until the issue is resolved.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-07973
CVE-2025-24330

Affected Products

Nokia Single Ran Baseband