Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, which in theory could potentially be used for causing resource exhaustion in the Single RAN baseband OAM service. No practical exploit has been detected for this flaw. However, the issue has been corrected starting from release 24R1-SR 2.1 MP by adding sufficient input validation for received SOAP requests, effectively mitigating the reported issue.
History

Wed, 02 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1287
Metrics cvssV3_1

{'score': 2, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Jul 2025 08:45:00 +0000

Type Values Removed Values Added
Description Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, which in theory could potentially be used for causing resource exhaustion in the Single RAN baseband OAM service. No practical exploit has been detected for this flaw. However, the issue has been corrected starting from release 24R1-SR 2.1 MP by adding sufficient input validation for received SOAP requests, effectively mitigating the reported issue.
Title SOAP message input validation fault could in theory cause OAM service resource exhaustion
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Nokia

Published: 2025-07-02T08:35:46.346Z

Updated: 2025-07-02T13:26:40.283Z

Reserved: 2025-01-20T05:33:25.524Z

Link: CVE-2025-24335

cve-icon Vulnrichment

Updated: 2025-07-02T13:17:39.339Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-02T09:15:25.010

Modified: 2025-07-03T15:13:53.147

Link: CVE-2025-24335

cve-icon Redhat

No data.