Directory Path Traversal in Nokia Airscale ASIKA Single RAN Devices
CVE-2023-25186
2.8LOW
What is CVE-2023-25186?
A vulnerability has been found in Nokia's Airscale ASIKA Single RAN devices prior to version 21B. This issue arises when a CSP (as a BTS administrator) disables critical security hardenings within the Nokia Single RAN BTS baseband unit. The flaw is in the diagnostic tool AaShell, which, although disabled by default, allows a directory path traversal. This can potentially grant unauthorized access to the internal filesystem of the BTS baseband unit through the management network of the mobile network solution, exposing it to risks such as unauthorized data access or manipulation.