« Volver al listado

CVE-2025-24335

Estado: AplazadaBaja (2)—

Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, which in theory could potentially be used for causing resource exhaustion in the Single RAN baseband OAM service.

No practical exploit has been detected for this flaw. However, the issue has been corrected starting from release 24R1-SR 2.1 MP by adding sufficient input validation for received SOAP requests, effectively mitigating the reported issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-24335",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-24335",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-02T13:26:34.467642Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 0.5
      }
    ]
  },
  "affected": [
    {
      "source": "b48c3b8f-639e-4c16-8725-497bc411dad0",
      "affectedData": [
        {
          "vendor": "Nokia",
          "product": "Nokia Single RAN",
          "versions": [
            {
              "status": "affected",
              "version": "All the releases prior to 24R1-SR 2.1 MP"
            },
            {
              "status": "unaffected",
              "version": "24R1-SR 2.1 MP and later"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-07-02T09:15:25.010",
  "references": [
    {
      "url": "https://www.nokia.com/about-us/security-and-privacy/product-security-advisory/cve-2025-24335/",
      "source": "b48c3b8f-639e-4c16-8725-497bc411dad0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, which in theory could potentially be used for causing resource exhaustion in the Single RAN baseband OAM service.\n\nNo practical exploit has been detected for this flaw. However, the issue has been corrected starting from release 24R1-SR 2.1 MP by adding sufficient input validation for received SOAP requests, effectively mitigating the reported issue."
    },
    {
      "lang": "es",
      "value": "Las versiones del software de banda base de Nokia Single RAN anteriores a la 24R1-SR 2.1 MP contienen una falla de validación de entrada de mensajes SOAP que, en teoría, podría utilizarse para causar el agotamiento de recursos en el servicio OAM de banda base de RAN única. No se ha detectado ninguna vulnerabilidad práctica para esta falla. Sin embargo, el problema se ha corregido a partir de la versión 24R1-SR 2.1 MP añadiendo una validación de entrada suficiente para las solicitudes SOAP recibidas, mitigando eficazmente el problema reportado."
    }
  ],
  "lastModified": "2026-06-17T08:58:35.113",
  "sourceIdentifier": "b48c3b8f-639e-4c16-8725-497bc411dad0"
}