Unauthenticated Access Vulnerability in Nokia Airscale ASIKA Single RAN Devices
CVE-2023-25188
7.8HIGH
What is CVE-2023-25188?
An identified issue in Nokia Airscale ASIKA Single RAN devices exposes a risk where baseline security hardening measures can be removed by a BTS administrator. This misconfiguration allows for potential unauthenticated access to the BTS baseband unit diagnostic tool, AaShell, which is disabled by default. Such access can compromise the integrity of the internally managed BTS system, specifically impacting the embedded Linux operating system utilized within these network components.