Directory Path Traversal in Nokia Airscale ASIKA Single RAN Devices
CVE-2023-25186

2.8LOW

Key Information:

Vendor
Nokia
Vendor
CVE Published:
16 June 2023

Summary

A vulnerability has been found in Nokia's Airscale ASIKA Single RAN devices prior to version 21B. This issue arises when a CSP (as a BTS administrator) disables critical security hardenings within the Nokia Single RAN BTS baseband unit. The flaw is in the diagnostic tool AaShell, which, although disabled by default, allows a directory path traversal. This can potentially grant unauthorized access to the internal filesystem of the BTS baseband unit through the management network of the mobile network solution, exposing it to risks such as unauthorized data access or manipulation.

References

CVSS V3.1

Score:
2.8
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.