CVE-2024-25008
Estado: AplazadaMedia (6.8)—
Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for example to obtain a Linux Shell with the same privileges as the attacker. The attacker would require elevated privileges for example a valid OAM user having the system administrator role to exploit the vulnerability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.29%
- Percentil entre todas las CVEs puntuadas: 20
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-25008",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-25008",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-08-16T13:14:44.851352Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "85b1779b-6ecd-4f52-bcc5-73eac4659dcf",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "85b1779b-6ecd-4f52-bcc5-73eac4659dcf",
"affectedData": [
{
"vendor": "Ericsson",
"product": "Ericsson RAN Compute Basebands (all BB variants)",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "24.Q2",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Ericsson",
"product": "Site Controller 6610",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "24.Q2",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:h:ericsson:controller_6610:*:*:*:*:*:*:*:*"
],
"vendor": "ericsson",
"product": "controller_6610",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "24.q2",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:2.3:h:ericsson:ran_compute:*:*:*:*:*:*:*:*"
],
"vendor": "ericsson",
"product": "ran_compute",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "24.q2",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-08-16T10:15:04.823",
"references": [
{
"url": "https://www.ericsson.com/en/about-us/security/psirt/security-bulletin-ericsson-ran-compute-august-2024",
"source": "85b1779b-6ecd-4f52-bcc5-73eac4659dcf"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "85b1779b-6ecd-4f52-bcc5-73eac4659dcf",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for example to obtain a Linux Shell with the same privileges as the attacker. The attacker would require elevated privileges for example a valid OAM user having the system administrator role to exploit the vulnerability."
},
{
"lang": "es",
"value": " Ericsson RAN Compute and Site Controller 6610 contiene una vulnerabilidad en el sistema de control donde la validación de entrada incorrecta puede provocar la ejecución de código arbitrario, por ejemplo, para obtener un shell de Linux con los mismos privilegios que el atacante. El atacante necesitaría privilegios elevados, por ejemplo, un usuario de OAM válido que tenga el rol de administrador del sistema para explotar la vulnerabilidad."
}
],
"lastModified": "2026-06-17T07:15:22.463",
"sourceIdentifier": "85b1779b-6ecd-4f52-bcc5-73eac4659dcf"
}