Sending a crafted SOAP "set" operation message within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause Nokia Single RAN baseband OAM service component restart with software versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected to release 24R1-SR 1.0 MP and later. The OAM service component restarts automatically after the stack overflow without causing a base station restart or network service degradation, and without leaving any permanent impact on the Nokia Single RAN baseband OAM service.
History

Wed, 02 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Jul 2025 07:45:00 +0000

Type Values Removed Values Added
Description Sending a crafted SOAP "set" operation message within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause Nokia Single RAN baseband OAM service component restart with software versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected to release 24R1-SR 1.0 MP and later. The OAM service component restarts automatically after the stack overflow without causing a base station restart or network service degradation, and without leaving any permanent impact on the Nokia Single RAN baseband OAM service.
Title OAM service stack overflow caused by crafted SOAP message within the MNO internal RAN management network
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Nokia

Published: 2025-07-02T07:39:30.318Z

Updated: 2025-07-02T13:45:17.927Z

Reserved: 2025-01-20T05:33:25.523Z

Link: CVE-2025-24328

cve-icon Vulnrichment

Updated: 2025-07-02T13:42:48.640Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-02T08:15:21.477

Modified: 2025-07-03T15:13:53.147

Link: CVE-2025-24328

cve-icon Redhat

No data.