Unauthenticated Access Vulnerability in Nokia Airscale ASIKA Single RAN Devices
CVE-2023-25188
7.8HIGH
Summary
An identified issue in Nokia Airscale ASIKA Single RAN devices exposes a risk where baseline security hardening measures can be removed by a BTS administrator. This misconfiguration allows for potential unauthenticated access to the BTS baseband unit diagnostic tool, AaShell, which is disabled by default. Such access can compromise the integrity of the internally managed BTS system, specifically impacting the embedded Linux operating system utilized within these network components.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved