CVE Vulnerabilities

CVE-2023-25188

Improper Privilege Management

Published: Jun 16, 2023 | Modified: Dec 12, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from the Nokia Single RAN BTS baseband unit, the BTS baseband unit diagnostic tool AaShell (which is by default disabled) allows unauthenticated access from the mobile network solution internal BTS management network to the BTS embedded Linux operating-system level.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Asika_airscale_firmwareNokia19b (including)19b (including)
Asika_airscale_firmwareNokia20a (including)20a (including)
Asika_airscale_firmwareNokia20b (including)20b (including)
Asika_airscale_firmwareNokia20c (including)20c (including)
Asika_airscale_firmwareNokia21a (including)21a (including)

Potential Mitigations

References