Sending a crafted SOAP "provision" operation message PlanId field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path traversal issue in Nokia Single RAN baseband software with versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected to release 24R1-SR 1.0 MP and later.
Beginning with release 24R1-SR 1.0 MP, the OAM service software performed PlanId field input validations mitigate the reported path traversal issue.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-22 | |
Metrics |
cvssV3_1
|
Wed, 02 Jul 2025 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Sending a crafted SOAP "provision" operation message PlanId field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path traversal issue in Nokia Single RAN baseband software with versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected to release 24R1-SR 1.0 MP and later. Beginning with release 24R1-SR 1.0 MP, the OAM service software performed PlanId field input validations mitigate the reported path traversal issue. | |
Title | OAM service path traversal issue caused by a crafted SOAP message PlanId field within the RAN management network | |
References |
|

Status: PUBLISHED
Assigner: Nokia
Published: 2025-07-02T08:29:03.339Z
Updated: 2025-07-02T14:39:50.109Z
Reserved: 2025-01-20T05:33:25.523Z
Link: CVE-2025-24330

Updated: 2025-07-02T14:39:26.803Z

Status : Awaiting Analysis
Published: 2025-07-02T09:15:24.500
Modified: 2025-07-03T15:13:53.147
Link: CVE-2025-24330

No data.