Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-25186


An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from a Nokia Single RAN BTS baseband unit, a directory path traversal in the Nokia BTS baseband unit diagnostic tool AaShell (which is by default disabled) provides access to the BTS baseband unit internal filesystem from the mobile network solution internal BTS management network.


Published

2023-06-16T19:15:14.423

Last Modified

2024-11-21T07:49:16.570

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System nokia asika_airscale_firmware 19b Yes
Operating System nokia asika_airscale_firmware 20a Yes
Operating System nokia asika_airscale_firmware 20b Yes
Operating System nokia asika_airscale_firmware 20c Yes
Operating System nokia asika_airscale_firmware 21a Yes
Hardware nokia asika_airscale - No

References