← Back

CVE-2023-25188

nvd nist
Published: Jun 16, 2023Modified: Dec 12, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from the Nokia Single RAN BTS baseband unit, the BTS baseband unit diagnostic tool AaShell (which is by default disabled) allows unauthenticated access from the mobile network solution internal BTS management network to the BTS embedded Linux operating-system level.

Affected (5)

1 product
Asika Airscale Firmware
Configuration A
5 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Nokia
Version 19b
Version 20a
Version 20b
Version 20c
Version 21a
Running on/withPlatform Versions
Nokia
Asika Airscale
All versions

References (4)

Source: cve@mitre.org
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.