PT-2025-27608 · Nokia · Nokia Single Ran Baseband
Guillaume Teissier
+3
·
Published
2025-07-02
·
Updated
2025-07-02
·
CVE-2025-24330
CVSS v2.0
6.5
Medium
| Vector | AV:A/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Nokia Single RAN baseband software versions prior to 24R1-SR 1.0 MP
Description:
The issue arises when a crafted SOAP "provision" operation message is sent with a malicious
PlanId field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network, causing a path traversal issue. This has been mitigated in release 24R1-SR 1.0 MP and later by performing PlanId field input validations in the OAM service software.Recommendations:
For versions prior to 24R1-SR 1.0 MP, update to release 24R1-SR 1.0 MP or later to resolve the issue. As a temporary workaround, consider restricting access to the SOAP "provision" operation message endpoint to minimize the risk of exploitation. Avoid using the
PlanId field in the affected API endpoint until the issue is resolved.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nokia Single Ran Baseband