CVE-2025-24335
Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, which in theory could potentially be used for causing resource exhaustion in the Single RAN baseband OAM service.
No practical exploit has been detected for this flaw. However, the issue has been corrected starting from release 24R1-SR 2.1 MP by adding sufficient input validation for received SOAP requests, effectively mitigating the reported issue.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
- Puntuación base: 2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.54%
- Percentil entre todas las CVEs puntuadas: 44
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-1287
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-24335",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-24335",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-07-02T13:26:34.467642Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 2,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "LOW",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 0.5
}
]
},
"affected": [
{
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"affectedData": [
{
"vendor": "Nokia",
"product": "Nokia Single RAN",
"versions": [
{
"status": "affected",
"version": "All the releases prior to 24R1-SR 2.1 MP"
},
{
"status": "unaffected",
"version": "24R1-SR 2.1 MP and later"
}
]
}
]
}
],
"published": "2025-07-02T09:15:25.010",
"references": [
{
"url": "https://www.nokia.com/about-us/security-and-privacy/product-security-advisory/cve-2025-24335/",
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-1287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, which in theory could potentially be used for causing resource exhaustion in the Single RAN baseband OAM service.\n\nNo practical exploit has been detected for this flaw. However, the issue has been corrected starting from release 24R1-SR 2.1 MP by adding sufficient input validation for received SOAP requests, effectively mitigating the reported issue."
},
{
"lang": "es",
"value": "Las versiones del software de banda base de Nokia Single RAN anteriores a la 24R1-SR 2.1 MP contienen una falla de validación de entrada de mensajes SOAP que, en teoría, podría utilizarse para causar el agotamiento de recursos en el servicio OAM de banda base de RAN única. No se ha detectado ninguna vulnerabilidad práctica para esta falla. Sin embargo, el problema se ha corregido a partir de la versión 24R1-SR 2.1 MP añadiendo una validación de entrada suficiente para las solicitudes SOAP recibidas, mitigando eficazmente el problema reportado."
}
],
"lastModified": "2026-06-17T08:58:35.113",
"sourceIdentifier": "b48c3b8f-639e-4c16-8725-497bc411dad0"
}