Input Validation Vulnerability in Nokia Single RAN Baseband Software
CVE-2025-24333
6.4MEDIUM
What is CVE-2025-24333?
The Nokia Single RAN baseband software is affected by an input validation flaw, allowing authenticated administrators to potentially execute arbitrary commands. This vulnerability is associated with the baseband's handling of special characters in the internal COMA_config.xml file, which could lead to unauthorized command execution within the unprivileged baseband OAM service process. This issue has been remediated in versions 24R1-SR 1.0 MP onward, where enhanced input validation measures were implemented to safeguard against such injection attempts.
Affected Version(s)
Nokia Single RAN All the releases prior to 24R1-SR 1.0 MP
Nokia Single RAN 24R1-SR 1.0 MP and later