Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path traversal issue in Nokia Single RAN baseband software with versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected to release 24R1-SR 1.0 MP and later. Beginning with release 24R1-SR 1.0 MP, the OAM service software utilizes libarchive APIs with security options enabled, effectively mitigating the reported path traversal issue.
History

Wed, 02 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Jul 2025 08:45:00 +0000

Type Values Removed Values Added
Description Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path traversal issue in Nokia Single RAN baseband software with versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected to release 24R1-SR 1.0 MP and later. Beginning with release 24R1-SR 1.0 MP, the OAM service software utilizes libarchive APIs with security options enabled, effectively mitigating the reported path traversal issue.
Title OAM service path traversal issue caused by a crafted SOAP message archive field within the RAN management network
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Nokia

Published: 2025-07-02T08:27:43.287Z

Updated: 2025-07-02T13:38:28.621Z

Reserved: 2025-01-20T05:33:25.523Z

Link: CVE-2025-24329

cve-icon Vulnrichment

Updated: 2025-07-02T13:36:51.964Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-02T09:15:24.390

Modified: 2025-07-03T15:13:53.147

Link: CVE-2025-24329

cve-icon Redhat

No data.