CVE Vulnerabilities

CVE-2023-25188

Improper Privilege Management

Published: Jun 16, 2023 | Modified: Jun 30, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from the Nokia Single RAN BTS baseband unit, the BTS baseband unit diagnostic tool AaShell (which is by default disabled) allows unauthenticated access from the mobile network solution internal BTS management network to the BTS embedded Linux operating-system level.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Asika_airscale_firmware Nokia 19b (including) 19b (including)
Asika_airscale_firmware Nokia 20a (including) 20a (including)
Asika_airscale_firmware Nokia 20b (including) 20b (including)
Asika_airscale_firmware Nokia 20c (including) 20c (including)
Asika_airscale_firmware Nokia 21a (including) 21a (including)

Potential Mitigations

References