Authentication Bypass in Nokia AirScale Baseband System
CVE-2025-24332

7.1HIGH

What is CVE-2025-24332?

The Nokia AirScale baseband system has been identified to allow an authenticated administrative user to access all physical boards through a single login. This occurs due to the lack of re-authentication when connecting from the baseband system board to the capacity boards via the internal bsoc SSH service. This internal service permits logins between boards using a private SSH key available on the system board. Recent updates have restricted this capability to baseband root-privileged administrators, enhancing security measures to prevent misuse by users with lower privileges. Users are urged to update to the latest software release to mitigate potential risks.

Affected Version(s)

Nokia Single RAN AirScale (Flexi Multiradio is not affected) All the releases prior to 23R4-SR 3.0 MP

Nokia Single RAN AirScale (Flexi Multiradio is not affected) 23R4-SR 3.0 MP and later

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-24332 : Authentication Bypass in Nokia AirScale Baseband System