Nokia Single RAN baseband software earlier than 24R1-SR 1.0 MP contains administrative shell input validation fault, which authenticated admin user can, in theory, potentially use for injecting arbitrary commands for unprivileged baseband OAM service process execution via special characters added to baseband internal COMA_config.xml file. This issue has been corrected starting from release 24R1-SR 1.0 MP and later, by adding proper input validation to OAM service process which prevents injecting special characters via baseband internal COMA_config.xml file.
History

Wed, 02 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Jul 2025 08:45:00 +0000

Type Values Removed Values Added
Description Nokia Single RAN baseband software earlier than 24R1-SR 1.0 MP contains administrative shell input validation fault, which authenticated admin user can, in theory, potentially use for injecting arbitrary commands for unprivileged baseband OAM service process execution via special characters added to baseband internal COMA_config.xml file. This issue has been corrected starting from release 24R1-SR 1.0 MP and later, by adding proper input validation to OAM service process which prevents injecting special characters via baseband internal COMA_config.xml file.
Title Administrative user shell input validation fault
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Nokia

Published: 2025-07-02T08:32:57.271Z

Updated: 2025-07-02T14:13:31.539Z

Reserved: 2025-01-20T05:33:25.524Z

Link: CVE-2025-24333

cve-icon Vulnrichment

Updated: 2025-07-02T14:13:06.188Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-02T09:15:24.800

Modified: 2025-07-03T15:13:53.147

Link: CVE-2025-24333

cve-icon Redhat

No data.