Unauthenticated Access Vulnerability in Nokia Airscale ASIKA Single RAN Devices
CVE-2023-25188

7.8HIGH

Key Information:

Vendor
Nokia
Vendor
CVE Published:
16 June 2023

Summary

An identified issue in Nokia Airscale ASIKA Single RAN devices exposes a risk where baseline security hardening measures can be removed by a BTS administrator. This misconfiguration allows for potential unauthenticated access to the BTS baseband unit diagnostic tool, AaShell, which is disabled by default. Such access can compromise the integrity of the internally managed BTS system, specifically impacting the embedded Linux operating system utilized within these network components.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.