Directory Path Traversal in Nokia Airscale ASIKA Single RAN Devices
CVE-2023-25186
2.8LOW
Summary
A vulnerability has been found in Nokia's Airscale ASIKA Single RAN devices prior to version 21B. This issue arises when a CSP (as a BTS administrator) disables critical security hardenings within the Nokia Single RAN BTS baseband unit. The flaw is in the diagnostic tool AaShell, which, although disabled by default, allows a directory path traversal. This can potentially grant unauthorized access to the internal filesystem of the BTS baseband unit through the management network of the mobile network solution, exposing it to risks such as unauthorized data access or manipulation.
References
CVSS V3.1
Score:
2.8
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved