SOAP Message Manipulation Vulnerability in Nokia Single RAN Baseband OAM Service
CVE-2025-24328
What is CVE-2025-24328?
A crafted SOAP 'set' operation message can exploit a vulnerability within Nokia's Single RAN baseband OAM service, leading to an automatic restart of the OAM service component. Importantly, this issue only affects versions prior to the 24R1-SR 1.0 MP release. While the OAM service restarts due to a stack overflow, the overall base station remains unaffected, ensuring that network services continue without degradation. This vulnerability has been addressed in subsequent software versions, improving the resilience of the service.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Nokia Single RAN All releases prior to 24R1-SR 1.0 MP are affected.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved