« Volver al listado

CVE-2025-24333

Estado: AplazadaMedia (6.4)—

Nokia Single RAN baseband software earlier than 24R1-SR 1.0 MP contains administrative shell input validation fault, which authenticated admin user can, in theory, potentially use for injecting arbitrary commands for unprivileged baseband OAM service process execution via special characters added to baseband internal COMA_config.xml file.

This issue has been corrected starting from release 24R1-SR 1.0 MP and later, by adding proper input validation to OAM service process which prevents injecting special characters via baseband internal COMA_config.xml file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-24333",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-24333",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-02T14:13:27.212792Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.5
      }
    ]
  },
  "affected": [
    {
      "source": "b48c3b8f-639e-4c16-8725-497bc411dad0",
      "affectedData": [
        {
          "vendor": "Nokia",
          "product": "Nokia Single RAN",
          "versions": [
            {
              "status": "affected",
              "version": "All the releases prior to 24R1-SR 1.0 MP"
            },
            {
              "status": "unaffected",
              "version": "24R1-SR 1.0 MP and later"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-07-02T09:15:24.800",
  "references": [
    {
      "url": "https://www.nokia.com/about-us/security-and-privacy/product-security-advisory/cve-2025-24333/",
      "source": "b48c3b8f-639e-4c16-8725-497bc411dad0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-77"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Nokia Single RAN baseband software earlier than 24R1-SR 1.0 MP contains administrative shell input validation fault, which authenticated admin user can, in theory, potentially use for injecting arbitrary commands for unprivileged baseband OAM service process execution via special characters added to baseband internal COMA_config.xml file.\n\nThis issue has been corrected starting from release 24R1-SR 1.0 MP and later, by adding proper input validation to OAM service process which prevents injecting special characters via baseband internal COMA_config.xml file."
    },
    {
      "lang": "es",
      "value": "El software de banda base de Nokia Single RAN anterior a la versión 24R1-SR 1.0 MP presenta un fallo de validación de entrada en el shell administrativo. Este fallo, en teoría, podría ser utilizado por un usuario administrador autenticado para inyectar comandos arbitrarios y ejecutar procesos de servicio OAM de banda base sin privilegios mediante la adición de caracteres especiales al archivo interno COMA_config.xml de banda base. Este problema se ha corregido a partir de la versión 24R1-SR 1.0 MP, añadiendo una validación de entrada adecuada al proceso de servicio OAM, lo que impide la inyección de caracteres especiales mediante el archivo interno COMA_config.xml de banda base."
    }
  ],
  "lastModified": "2026-06-17T08:58:34.847",
  "sourceIdentifier": "b48c3b8f-639e-4c16-8725-497bc411dad0"
}