Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-25188


An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from the Nokia Single RAN BTS baseband unit, the BTS baseband unit diagnostic tool AaShell (which is by default disabled) allows unauthenticated access from the mobile network solution internal BTS management network to the BTS embedded Linux operating-system level.


Published

2023-06-16T19:15:14.477

Last Modified

2024-12-12T19:15:07.413

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-269
  • Type: Secondary
    CWE-346

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System nokia asika_airscale_firmware 19b Yes
Operating System nokia asika_airscale_firmware 20a Yes
Operating System nokia asika_airscale_firmware 20b Yes
Operating System nokia asika_airscale_firmware 20c Yes
Operating System nokia asika_airscale_firmware 21a Yes
Hardware nokia asika_airscale - No

References