CVE Vulnerabilities

CVE-2023-25185

Improper Privilege Management

Published: Jun 16, 2023 | Modified: Dec 12, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN software releases. Certain software processes in the BTS internal software design have unnecessarily high privileges to BTS embedded operating system (OS) resources.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Asika_airscale_firmwareNokia19b (including)19b (including)
Asika_airscale_firmwareNokia20a (including)20a (including)
Asika_airscale_firmwareNokia20b (including)20b (including)
Asika_airscale_firmwareNokia20c (including)20c (including)
Asika_airscale_firmwareNokia21a (including)21a (including)

Potential Mitigations

References