Unauthenticated Access Vulnerability in Nokia Airscale ASIKA Single RAN Devices
CVE-2023-25188
5.1MEDIUM
What is CVE-2023-25188?
An identified issue in Nokia Airscale ASIKA Single RAN devices exposes a risk where baseline security hardening measures can be removed by a BTS administrator. This misconfiguration allows for potential unauthenticated access to the BTS baseband unit diagnostic tool, AaShell, which is disabled by default. Such access can compromise the integrity of the internally managed BTS system, specifically impacting the embedded Linux operating system utilized within these network components.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved