SOAP Message Manipulation Vulnerability in Nokia Single RAN Baseband OAM Service
CVE-2025-24328

4.2MEDIUM

Key Information:

Vendor

Nokia

Vendor
CVE Published:
2 July 2025

What is CVE-2025-24328?

A crafted SOAP 'set' operation message can exploit a vulnerability within Nokia's Single RAN baseband OAM service, leading to an automatic restart of the OAM service component. Importantly, this issue only affects versions prior to the 24R1-SR 1.0 MP release. While the OAM service restarts due to a stack overflow, the overall base station remains unaffected, ensuring that network services continue without degradation. This vulnerability has been addressed in subsequent software versions, improving the resilience of the service.

Affected Version(s)

Nokia Single RAN All releases prior to 24R1-SR 1.0 MP are affected.

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.